- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hi guys, this is a 101 question - how does SASE determine of the user is in the office or elsewhere?
We are having repeated issues of users getting a message "no internet connection" whilst in the office, the wireless logs say they are still connected, I suspect SASE is failing the in the office test maybe due to latency/loss or wifi roaming, then connecting itself, which is not going to work in the office and break their Internet.
Is there any way I can confirm this? I presume it tries to access the local DNS server. When the users are in the office I see constant attempts to an unknown DNS server which is blocked, is the check a reverse check perhaps, ie if I can see this Ip then they are not in the office?
That's the end user side.
The Infinity Portal side is where you can configure when the "Always-on VPN" terminates because it is in a trusted environment.
It is looking for (and you can configure):
Nm, got it. Went to chat and guy was super helpful, told me right away 🙂
Under users -> user profiles
Andy
I can check in our lab tomorrow, but Im fairly sure it goes with combination of posture check/ZTNA and there is also setting on the agent for wi-fi, but cant recall exactly what...will check on the agent. It might be also related to geolocation setting as well.
Andy
Appreciated thanks!
Of course!
That's the end user side.
The Infinity Portal side is where you can configure when the "Always-on VPN" terminates because it is in a trusted environment.
It is looking for (and you can configure):
Ah, since I dont have access to that, I was trying to find it on perimeter81.com site portal, but dont see where : - (
Andy
that's great thank you both,
Confirmed we have trusted environment enable and the router mac address is correctly specified.
Sounds like you are all set. If you need anything else tested, let us know. I have access to our company lab environment, but can check any other settings in live client's environment as well.
If it helps, below is some info I gathered from the lab my colleague and I did recently.
https://community.checkpoint.com/t5/SASE/Harmony-SASE-lab-doc/m-p/244114
Andy
Here, the option to use the router's MAC address didn't work very well. On the other hand, the Trusted Web Server option is working perfectly. However, I had to open a support ticket, and they sent me a version (11.6) of the agent that isn't available for download on the portal — at least not in my workspace.
I believe the Router MAC can only be detected if it's on the same L2 network as the end user.
A Trusted Web Server seems more likely to work in more situations.
Wed 05 Nov 2025 @ 08:00 AM (IST)
Your First Response: Immediate Actions for Cyber Incident Containment - AMERWed 05 Nov 2025 @ 11:00 AM (EST)
TechTalk: Access Control and Threat Prevention Best PracticesWed 05 Nov 2025 @ 08:00 AM (IST)
Your First Response: Immediate Actions for Cyber Incident Containment - AMERWed 05 Nov 2025 @ 11:00 AM (EST)
TechTalk: Access Control and Threat Prevention Best PracticesThu 06 Nov 2025 @ 10:00 AM (CET)
CheckMates Live BeLux: Get to Know Veriti – What It Is, What It Does, and Why It MattersTue 11 Nov 2025 @ 10:00 AM (CET)
Your First Response: Immediate Actions for Cyber Incident Containment- EMEAThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERTue 11 Nov 2025 @ 06:00 PM (COT)
San Pedro Sula: Risk Management al Horno: ERM, TEM & Pizza NightTue 11 Nov 2025 @ 06:00 PM (COT)
San Pedro Sula: Risk Management al Horno: ERM, TEM & Pizza NightAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY