Correct Answer: D
You can establish a VPN before the user login to the Endpoint Client by enabling Machine Authentication in the Gateway object of the Smart Console1. Machine Authentication is a feature that allows you to authenticate with a machine certificate and establish a VPN tunnel before the Windows Logon2. This feature provides the following benefits2:
* It enhances the security of the VPN connection by verifying the identity of the machine before allowing access to the network.
* It simplifies the user experience by eliminating the need to enter credentials twice (once for the VPN and once for the Windows Logon).
* It enables seamless connectivity to the network resources and domain services, such as Group Policy, login scripts, and mapped drives. Machine Authentication is supported on Check Point Endpoint Security Client for Windows with E80.71 and higher versions2. It requires a hotfix on top of R77.30 jumbo 286 on the Security Gateway2. To configure Machine Authentication, you need to do the following steps2:
* Generate and distribute machine certificates to the Endpoint machines using a trusted Certificate Authority (CA).
* Enable Machine Authentication in the Gateway object of the Smart Console and select the CA that issued the machine certificates.
* Install policy on the Security Gateway and reboot it.
* Enable Machine Authentication in the Endpoint Security Client and select the machine certificate to use.