- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi guys, this is a 101 question - how does SASE determine of the user is in the office or elsewhere?
We are having repeated issues of users getting a message "no internet connection" whilst in the office, the wireless logs say they are still connected, I suspect SASE is failing the in the office test maybe due to latency/loss or wifi roaming, then connecting itself, which is not going to work in the office and break their Internet.
Is there any way I can confirm this? I presume it tries to access the local DNS server. When the users are in the office I see constant attempts to an unknown DNS server which is blocked, is the check a reverse check perhaps, ie if I can see this Ip then they are not in the office?
That's the end user side.
The Infinity Portal side is where you can configure when the "Always-on VPN" terminates because it is in a trusted environment.
It is looking for (and you can configure):
Nm, got it. Went to chat and guy was super helpful, told me right away 🙂
Under users -> user profiles
Andy
I can check in our lab tomorrow, but Im fairly sure it goes with combination of posture check/ZTNA and there is also setting on the agent for wi-fi, but cant recall exactly what...will check on the agent. It might be also related to geolocation setting as well.
Andy
Appreciated thanks!
Of course!
That's the end user side.
The Infinity Portal side is where you can configure when the "Always-on VPN" terminates because it is in a trusted environment.
It is looking for (and you can configure):
Ah, since I dont have access to that, I was trying to find it on perimeter81.com site portal, but dont see where : - (
Andy
that's great thank you both,
Confirmed we have trusted environment enable and the router mac address is correctly specified.
Sounds like you are all set. If you need anything else tested, let us know. I have access to our company lab environment, but can check any other settings in live client's environment as well.
If it helps, below is some info I gathered from the lab my colleague and I did recently.
https://community.checkpoint.com/t5/SASE/Harmony-SASE-lab-doc/m-p/244114
Andy
Here, the option to use the router's MAC address didn't work very well. On the other hand, the Trusted Web Server option is working perfectly. However, I had to open a support ticket, and they sent me a version (11.6) of the agent that isn't available for download on the portal — at least not in my workspace.
I believe the Router MAC can only be detected if it's on the same L2 network as the end user.
A Trusted Web Server seems more likely to work in more situations.
Fri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY