If you want your login secure, you can't trust the dial-in account. Anybody could have hijacked the dial-in computer/account, but without a proper login password, he/she could not login. This means your system is more secure.
When a user dials in, they will need to login with their user name and password. So you can use their (encrypted) dial-in username and password when you set the cookie. This way the dial-up user does not have to re-login.