Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
jamesdean-1
Participant
Jump to solution

SASE determine user location

Hi guys, this is a 101 question - how does SASE determine of the user is in the office or elsewhere?

We are having repeated issues of users getting a message "no internet connection" whilst in the office, the wireless logs say they are still connected, I suspect SASE is failing the in the office test maybe due to latency/loss or wifi roaming,  then connecting itself, which is not going to work in the office and break their Internet.

 

Is there any way I can confirm this? I presume it tries to access the local DNS server. When the users are in the office I see constant attempts to an unknown DNS server which is blocked, is the check a reverse check perhaps, ie if I can see this Ip then they are not in the office?

 

0 Kudos
2 Solutions

Accepted Solutions
PhoneBoy
Admin
Admin

That's the end user side.
The Infinity Portal side is where you can configure when the "Always-on VPN" terminates because it is in a trusted environment.
It is looking for (and you can configure):

  • A trusted web server only accessible when on-premise (specify the CA of this server)
  • Router MAC address

image.png

View solution in original post

the_rock
Legend
Legend

Nm, got it. Went to chat and guy was super helpful, told me right away 🙂

Under users -> user profiles

Andy

View solution in original post

0 Kudos
12 Replies
the_rock
Legend
Legend

I can check in our lab tomorrow, but Im fairly sure it goes with combination of posture check/ZTNA and there is also setting on the agent for wi-fi, but cant recall exactly what...will check on the agent. It might be also related to geolocation setting as well.

Andy

0 Kudos
jamesdean-1
Participant

Appreciated thanks!

the_rock
Legend
Legend

Of course!

0 Kudos
the_rock
Legend
Legend

How is attached set up?

Andy

 

0 Kudos
PhoneBoy
Admin
Admin

That's the end user side.
The Infinity Portal side is where you can configure when the "Always-on VPN" terminates because it is in a trusted environment.
It is looking for (and you can configure):

  • A trusted web server only accessible when on-premise (specify the CA of this server)
  • Router MAC address

image.png

the_rock
Legend
Legend

Ah, since I dont have access to that, I was trying to find it on perimeter81.com site portal, but dont see where : - (

Andy

0 Kudos
the_rock
Legend
Legend

Nm, got it. Went to chat and guy was super helpful, told me right away 🙂

Under users -> user profiles

Andy

0 Kudos
jamesdean-1
Participant

that's great thank you both,

 

Confirmed we have trusted environment enable and the router mac address is correctly specified.

0 Kudos
the_rock
Legend
Legend

Sounds like you are all set. If you need anything else tested, let us know. I have access to our company lab environment, but can check any other settings in live client's environment as well.

If it helps, below is some info I gathered from the lab my colleague and I did recently.

https://community.checkpoint.com/t5/SASE/Harmony-SASE-lab-doc/m-p/244114

Andy

0 Kudos
Gustavo_Ferreir
Contributor

Here, the option to use the router's MAC address didn't work very well. On the other hand, the Trusted Web Server option is working perfectly. However, I had to open a support ticket, and they sent me a version (11.6) of the agent that isn't available for download on the portal — at least not in my workspace.

0 Kudos
the_rock
Legend
Legend

Are you referring to what I attached?

Andy

PhoneBoy
Admin
Admin

I believe the Router MAC can only be detected if it's on the same L2 network as the end user.
A Trusted Web Server seems more likely to work in more situations.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events