Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Pierre_Bienaime
Participant

Check Point Endpoint Security VPN Service only on company-owned devices

Hi Fellow Checkmate Members 

Can anyone help me in achieving this for my company pretty please

Scenario:

We are using "Check Point Endpoint Security" as a remote access client for VPN users. It is working great with no problem. We are currently "Username+Password" as an authentication mechanism.  The problem we are having is the following:

Users can install the client on their own personal devices and connect to the VPN because they are allowed to. Now we want to limit Remove Access VPN connection ONLY using company-owned or company-assigned devices to the user. How do I go about achieving that? We are trying to prevent users from installing the Check Point Endpoint Security client to their personal devices, while not removing their Remote access VPN right on company-owned devices. Please help 😔 

 
 
0 Kudos
7 Replies
PhoneBoy
Admin
Admin

This is the kind of thing Endpoint Compliance should solve.
A thread that discusses this is here: https://community.checkpoint.com/t5/Remote-Access-Solutions/Restricting-access-to-corporate-devices/...
You can also achieve something similar with SCV.
See: https://community.checkpoint.com/t5/Remote-Access-Solutions/White-Paper-Check-Point-Compliance-Check...
Chris_Atkinson
Employee Employee
Employee

R80.40 may yield a feature of interest...

Remote Access VPN

Use machine certificate to distinguish between corporate and non-corporate assets and to set a policy  enforcing the use of corporate assets only. Enforcement can be pre-logon (device authentication only) or post-logon (device and user authentication).

CCSM R77/R80/ELITE
Pierre_Bienaime
Participant

Thank you Chris,
This is the path that I am intending to take, but I want to know how to I go about the certificate registration process
0 Kudos
Pierre_Bienaime
Participant

That is a very good approach PhoneBoy thank you. I will dive through the links to have a deeper understanding
0 Kudos
Tommy_Forrest
Advisor

Change your authentication method so that it is Username+Password+Certificate and only agree to allow them to register a corporate device with the generated Certificate.

While it isn't impossible to export certificates off of a Windows box, it takes some work to get it done and is beyond the capabilities of most users.

Pierre_Bienaime
Participant

Hi Tommy ,
That is the route that I am currently exploring. I see that you have mentioned the Registration of a Corporate device. I am not familiar with how to process will go after enabling the use of "Username+Password+Certificate" on my perimeter Gateways. I do not have a sandbox environment to try, and I want a clear path as to what would follow to complete the process after enabling the setting. I am glad you have mentioned this process, and if I can get a follow up on that, it will be great, thank you in advance
0 Kudos
Di_Junior
Advisor
Advisor

Hi Pierre

Did you perhaps found a solution for this?

Thanks in advance
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events