<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Possible to use Harmony Endpoint Application Control capability without activating the Firewall in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268359#M11209</link>
    <description>&lt;P&gt;Im fairly certain that enabling fw blade on harmony endpoint would effectively override windows defender built in firewall and your GPO rules would also be affected.&lt;/P&gt;
&lt;P&gt;Maybe best to open TAC case to confirm.&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jan 2026 04:36:25 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2026-01-23T04:36:25Z</dc:date>
    <item>
      <title>Possible to use Harmony Endpoint Application Control capability without activating the Firewall one?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268345#M11202</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;I am seeking some clarifications on how the Harmony Endpoint Application Control &amp;amp; Firewall capabilities can be used from experts in the community.&lt;/P&gt;&lt;P&gt;I would like to use Application Control in my context to manage allowed/blocked applications in production environment, but I don't really have a need to use the Firewall capability in Harmony Endpoint. The firewall part is already managed in a separate way (MS GPOs, etc.) and I do not want / need to activate the Firewall capability in Harmony Endpoint, only the Application Control part, &lt;STRONG&gt;is that possible?&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;From what I understand (based on the admin guide and my experience with the product), both seem to be merged together under the same blade and it does not seem to be possible... unless I am missing something:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Under software deployment the capabilities are enabled together, I do not know any way to just enable Application Control for example&lt;/LI&gt;&lt;LI&gt;Both seem to rely on a service called "Check Point Endpoint Security Network Protection", which only appears on the endpoint when the combined blade above is enabled.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Even if the Firewall capability must be activated, I do not see any way in the Harmony management console to disable it, you can only edit the Firewall inboud/outbound rulebase or manage objects.. If you have no choice but to enable it together to use Application Control, how to negate its effects? Disable all rules in the rulebase and it will not do anything or interfere in any way with the Windows firewall / Defender on the machine? Or it will anyway override and take over the Windows Firewall as long as it is enabled?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;In short, is there a way to bypass / disable the Firewall capability and just use Application Control only?&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I have attached a couple of screenshots as well to illustrate the point.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your help.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 02:05:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268345#M11202</guid>
      <dc:creator>dt7</dc:creator>
      <dc:date>2026-01-23T02:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to use Harmony Endpoint Application Control capability without activating the Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268346#M11203</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/54260"&gt;@dt7&lt;/a&gt;&amp;nbsp;You asked:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;In short, is there a way to bypass / disable the Firewall capability and just use Application Control only?&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I am fairly sure there is no way to bypass it. For the lack of better term, I would call them as a bundle "Network protection"&lt;/P&gt;
&lt;P&gt;You are more than welcome to verify with TAC, but Im 99.99% sure they will tell you the same. I will leave 0.01% I am wrong...would not be first OR last time lol&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 02:15:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268346#M11203</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-23T02:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to use Harmony Endpoint Application Control capability without activating the Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268347#M11204</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;Noted..&lt;/P&gt;&lt;P&gt;In that case, do you know how to negate the impact of having Firewall enabled? Does it deactivate the Windows firewall by default as long as the Firewall feature is enabled or there is a way to ignore the processing in Harmony and leave it to the OS as it was?&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Disable all the rules under Firewall inbound / outbound?/&lt;/LI&gt;&lt;LI&gt;Use any/any allow in both?&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Fri, 23 Jan 2026 02:20:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268347#M11204</guid>
      <dc:creator>dt7</dc:creator>
      <dc:date>2026-01-23T02:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to use Harmony Endpoint Application Control capability without activating the Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268348#M11205</link>
      <description>&lt;P&gt;Yes, you can do that. Technically, it would be same as in say regular CP firewall, or any fw, for that matter, you can always create rules to allow/bypass specific subnets/ports. But then, it begs the question, why even have the blade enabled or use the firewall?&lt;/P&gt;
&lt;P&gt;I get your dilemma (for the lack of the better word), but it sure sounds if you totally disabled the blade, then you would need to rely on windows built in firewall to allow/block specific services on the PC.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 02:23:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268348#M11205</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-23T02:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to use Harmony Endpoint Application Control capability without activating the Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268354#M11206</link>
      <description>&lt;P&gt;Yes but this is fine, I already manage the necessary via built-in Windows firewall / GPOs, I basically just want to use Application Control and do not want to enable Firewall in Harmony Endpoint ideally.&lt;/P&gt;&lt;P&gt;The problem is that it seems you cannot just enable Application Control without enabling Firewall in Harmony, so how to basically make sure it does not interfere with the builtin Windows firewall even if it is enabled, as I don't plan on using that capability (ideally) in Harmony.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 03:26:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268354#M11206</guid>
      <dc:creator>dt7</dc:creator>
      <dc:date>2026-01-23T03:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to use Harmony Endpoint Application Control capability without activating the Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268355#M11207</link>
      <description>&lt;P&gt;I totally get what you are saying now. Thats a bit of "catch 22" situation, if you will. Does not appear those blades can be "separated", so technically, best thing to do would be enable it, and then keep making exceptions as needed via policy.&lt;/P&gt;
&lt;P&gt;Makes sense?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 03:34:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268355#M11207</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-23T03:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to use Harmony Endpoint Application Control capability without activating the Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268358#M11208</link>
      <description>&lt;P&gt;Yes makes sense, as long as enabling the Firewall capability in Harmony does not completely override the built-in Windows firewall managed by GPOs, do you know if that's the case?&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, if you enable Harmony Endpoint antimalware blade, it auto-disables Windows Defender. If the same thing happens when enabling Firewall in Harmony, then making exceptions or allowing "any" in Harmony Firewall will actually create a security hole in the previous configuration instead..&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 04:22:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268358#M11208</guid>
      <dc:creator>dt7</dc:creator>
      <dc:date>2026-01-23T04:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to use Harmony Endpoint Application Control capability without activating the Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268359#M11209</link>
      <description>&lt;P&gt;Im fairly certain that enabling fw blade on harmony endpoint would effectively override windows defender built in firewall and your GPO rules would also be affected.&lt;/P&gt;
&lt;P&gt;Maybe best to open TAC case to confirm.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 04:36:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268359#M11209</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-23T04:36:25Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to use Harmony Endpoint Application Control capability without activating the Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268374#M11210</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Technically, you must deploy to both blades simultaneously; you can not unselect FW or App blade from deployment rules or package export rules. You can do this while editing the FW blade policies. To bypass the firewall functionality, you can configure the Inbound and Outbound policies as &lt;/SPAN&gt;Any–Any–Allow&lt;SPAN&gt; and disable logging.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 09:03:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268374#M11210</guid>
      <dc:creator>TurgutKaplanogl</dc:creator>
      <dc:date>2026-01-23T09:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to use Harmony Endpoint Application Control capability without activating the Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268538#M11212</link>
      <description>&lt;PRE id="tw-target-text" class="tw-data-text tw-text-large tw-ta" dir="ltr" tabindex="-1" role="text" data-placeholder="Tradução" data-ved="2ahUKEwjZye6Po6SSAxWiHLkGHbVMJ1oQ3ewLegQIDBAW" aria-label="Texto traduzido: Honestly, with the Checkpoint firewall you have the possibility to create many more features than the Windows firewall, besides log management and subnet management.

Among the possibilities:

1- Better rule management
2- Log visualization
3- Subnet microsegmentation"&gt;&lt;SPAN class="Y2IQFc"&gt;Honestly, with the Checkpoint firewall you have the possibility to create many more features than the Windows firewall, besides log management and subnet management.

Among the possibilities:

1- Better rule management
2- Log visualization
3- Subnet microsegmentation&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 24 Jan 2026 13:30:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268538#M11212</guid>
      <dc:creator>lluner</dc:creator>
      <dc:date>2026-01-24T13:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to use Harmony Endpoint Application Control capability without activating the Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268539#M11213</link>
      <description>&lt;P&gt;I was hoping you would reply...I was going to tag you, but then could not remember your username.&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/87055"&gt;@lluner&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jan 2026 13:31:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268539#M11213</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-24T13:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to use Harmony Endpoint Application Control capability without activating the Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268881#M11231</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;Please let us know if you were able to sort this out? It would be good to know if anyone else encounters the same dilemma.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jan 2026 00:46:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268881#M11231</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-28T00:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to use Harmony Endpoint Application Control capability without activating the Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268905#M11233</link>
      <description>&lt;P&gt;Are you able to manage the different zones in Harmony Firewall as well? Such as domain firewall, private and public? This can be done by GPO, but I am not sure how the same thing can be achieved using Check Point firewall, if you have any inputs that would be great.&lt;/P&gt;&lt;P&gt;In addition, what do you mean exactly by 3- Subnet microsegmentation? Is it the fact that all traffic will go through the Check Point firewall on the client and so you can also isolate the device within its own connected subnet for example to block traffic from machines in the same subnet?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jan 2026 07:17:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268905#M11233</guid>
      <dc:creator>dt7</dc:creator>
      <dc:date>2026-01-28T07:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to use Harmony Endpoint Application Control capability without activating the Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268916#M11234</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/54260"&gt;@dt7&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Are you able to manage the different zones in Harmony Firewall as well? Such as domain firewall, private and public? This can be done by GPO, but I am not sure how the same thing can be achieved using Check Point firewall, if you have any inputs that would be great.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;R:.You can do this on the Checkpoint firewall; it works as both inbound and outbound.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In addition, what do you mean exactly by 3- Subnet microsegmentation? Is it the fact that all traffic will go through the Check Point firewall on the client and so you can also isolate the device within its own connected subnet for example to block traffic from machines in the same subnet?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;R:.&amp;nbsp;You can do it all&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The granularity of the firewall is up to your imagination.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jan 2026 10:00:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/268916#M11234</guid>
      <dc:creator>lluner</dc:creator>
      <dc:date>2026-01-28T10:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to use Harmony Endpoint Application Control capability without activating the Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/269013#M11235</link>
      <description>&lt;P&gt;Hello, I haven't fully tested this part yet, but I will eventually in order to validate what has been discussed. If I have more helpful information on this, I will try to post it at a later date yes so that it can help others.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2026 04:12:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/269013#M11235</guid>
      <dc:creator>dt7</dc:creator>
      <dc:date>2026-01-29T04:12:15Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to use Harmony Endpoint Application Control capability without activating the Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/269014#M11236</link>
      <description>&lt;P&gt;Excellent, thanks for letting us know!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2026 04:13:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Possible-to-use-Harmony-Endpoint-Application-Control-capability/m-p/269014#M11236</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-29T04:13:24Z</dc:date>
    </item>
  </channel>
</rss>

