<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Blade not disabled after endpoint moves to different software deployment rule in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/VPN-Blade-not-disabled-after-endpoint-moves-to-different/m-p/252749#M10645</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Historically, when performing version upgrades on Check Point Harmony Endpoint, we temporarily moved selected endpoints into a deployment group associated with a higher-priority Software Deployment rule. This rule allowed endpoints to upgrade to the latest version and temporarily activated the Remote Access VPN blade. After testing, endpoints were returned to their original groups, applying a different deployment rule configured with an earlier software version and with the VPN blade explicitly disabled. Previously, this correctly disabled the VPN blade.&lt;/P&gt;&lt;P&gt;However, since upgrading to Harmony Endpoint version 88.70.0326, we've noticed that when endpoints move back to their original group (associated with the software deployment rule that explicitly disables the VPN blade), the VPN blade remains active despite the correct rule assignment. This behavior differs from earlier Harmony Endpoint versions where the VPN blade correctly reverted to the disabled state based on the software deployment rule.&lt;/P&gt;&lt;P&gt;I'm aware that creating an additional deployment group specifically configured to disable the VPN blade would be a workaround but I'd like to understand why this behavior has changed.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 08 Jul 2025 11:55:49 GMT</pubDate>
    <dc:creator>user856328</dc:creator>
    <dc:date>2025-07-08T11:55:49Z</dc:date>
    <item>
      <title>VPN Blade not disabled after endpoint moves to different software deployment rule</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-Blade-not-disabled-after-endpoint-moves-to-different/m-p/252749#M10645</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Historically, when performing version upgrades on Check Point Harmony Endpoint, we temporarily moved selected endpoints into a deployment group associated with a higher-priority Software Deployment rule. This rule allowed endpoints to upgrade to the latest version and temporarily activated the Remote Access VPN blade. After testing, endpoints were returned to their original groups, applying a different deployment rule configured with an earlier software version and with the VPN blade explicitly disabled. Previously, this correctly disabled the VPN blade.&lt;/P&gt;&lt;P&gt;However, since upgrading to Harmony Endpoint version 88.70.0326, we've noticed that when endpoints move back to their original group (associated with the software deployment rule that explicitly disables the VPN blade), the VPN blade remains active despite the correct rule assignment. This behavior differs from earlier Harmony Endpoint versions where the VPN blade correctly reverted to the disabled state based on the software deployment rule.&lt;/P&gt;&lt;P&gt;I'm aware that creating an additional deployment group specifically configured to disable the VPN blade would be a workaround but I'd like to understand why this behavior has changed.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jul 2025 11:55:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-Blade-not-disabled-after-endpoint-moves-to-different/m-p/252749#M10645</guid>
      <dc:creator>user856328</dc:creator>
      <dc:date>2025-07-08T11:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Blade not disabled after endpoint moves to different software deployment rule</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-Blade-not-disabled-after-endpoint-moves-to-different/m-p/252760#M10646</link>
      <description>&lt;P&gt;It is best to open a support call for this issue: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jul 2025 12:54:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-Blade-not-disabled-after-endpoint-moves-to-different/m-p/252760#M10646</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-08T12:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Blade not disabled after endpoint moves to different software deployment rule</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-Blade-not-disabled-after-endpoint-moves-to-different/m-p/252763#M10647</link>
      <description>&lt;P&gt;I second what Val said, definitely best thing to do.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jul 2025 13:17:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-Blade-not-disabled-after-endpoint-moves-to-different/m-p/252763#M10647</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-08T13:17:51Z</dc:date>
    </item>
  </channel>
</rss>

