- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Split Policy for Internal Users and Contractors - ...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Split Policy for Internal Users and Contractors - VPN
Hello Checkpoint Checkmates,
I got some queries from customer regarding how CP best practice for splitting policy for internal users and contractors.
Any possibility with single office mode IP to split the segment for internal users[AD integration] and contractors[local database]? So i can create 2 VPN policies based on the segment IP.
What is the best practice from CP for split policy from AD Users and Local Database? I think this is possible, but i lack of knowledge about this.
Suggestion or input are welcome 🙂 Thankyou
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Instead making rules based on IP I would make then the rules based on AD group and or local group. Blade Identity Awareness would help then.
I assume you do not have Endpoint? Then you could do stuff with desktop security.
If you like this post please give a thumbs up(kudo)! 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, we have Endpoint solution use harmony endpoint. Any suggestion to combine VPN and endpoint agent based on these request?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@Lesley hit the nail on the head, as they say. Put it this way, identity awareness blade is "golden" in such cases, because it will ALWAYS follow the user, regardless where they log in. If you dont have that enabled, good luck "chasing" the user.
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thanks @the_rock let me check for this feature and possibility in the customer env.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I really think it would help you.
Andy
