<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Initial client including VPN site in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Initial-client-including-VPN-site/m-p/277218#M11437</link>
    <description>&lt;P&gt;Are you using the Endpoint Security / Harmony Endpoint suite? Or just the VPN-only client? &amp;nbsp;You can't use the Initial Client with the VPN-only client (the unmanaged client).&lt;/P&gt;
&lt;P&gt;With the Harmony Endpoint suite, the Initial Client is created with the address of the Endpoint/Harmony Security server defined when you export the package from the package deployment. &amp;nbsp;Initial Client is to be used when users are already on your network somewhere and have direct access to the Endpoint server (assuming you're not using the cloud service). &amp;nbsp;If your users are remote-only, then you need to send them a full package with the VPN site and feature blades pre-defined.&lt;/P&gt;
&lt;P&gt;When you do this, be sure you have a Software Deployment rule configured that will match the blades and components of the exported package; otherwise, when the client installs, the first thing it does is check the Software Deployment rules for any blade updates (install/remove blades) before it tries to load a policy. &amp;nbsp;This may result in multiple reboots while the client is trying to align itself with the server.&lt;/P&gt;
&lt;P&gt;Hope that helps!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 20 May 2026 14:15:43 GMT</pubDate>
    <dc:creator>Duane_Toler</dc:creator>
    <dc:date>2026-05-20T14:15:43Z</dc:date>
    <item>
      <title>Initial client including VPN site</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Initial-client-including-VPN-site/m-p/277196#M11434</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I’ve recently switched our deployment strategy to use the Check Point &lt;STRONG&gt;Initial Client &lt;/STRONG&gt;to ensure our endpoints always fetch and install the latest available version.&lt;/P&gt;&lt;P&gt;However, because the initial client package is generic, it installs without our custom VPN site pre-configured.&lt;/P&gt;&lt;P&gt;Could anyone share the best practices or scripts to automate the VPN site configuration locally on the endpoint immediately after the initial client installs?&lt;/P&gt;&lt;P&gt;&lt;I&gt;Note: We are not motivated to use a centralized push operation from the portal.&lt;/I&gt;&lt;/P&gt;&lt;P&gt;Any hints, scripts, or documentation references would be highly appreciated!&lt;/P&gt;&lt;P&gt;Cheers, Olli&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 12:58:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Initial-client-including-VPN-site/m-p/277196#M11434</guid>
      <dc:creator>CP-Shark</dc:creator>
      <dc:date>2026-05-20T12:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Initial client including VPN site</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Initial-client-including-VPN-site/m-p/277214#M11436</link>
      <description>&lt;P&gt;While the paths are different, you should be able to use the CLI to add a site:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk55620" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk55620&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;The other option would be to replace trac.config on the client:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk183469" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk183469&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 14:11:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Initial-client-including-VPN-site/m-p/277214#M11436</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-05-20T14:11:28Z</dc:date>
    </item>
    <item>
      <title>Re: Initial client including VPN site</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Initial-client-including-VPN-site/m-p/277218#M11437</link>
      <description>&lt;P&gt;Are you using the Endpoint Security / Harmony Endpoint suite? Or just the VPN-only client? &amp;nbsp;You can't use the Initial Client with the VPN-only client (the unmanaged client).&lt;/P&gt;
&lt;P&gt;With the Harmony Endpoint suite, the Initial Client is created with the address of the Endpoint/Harmony Security server defined when you export the package from the package deployment. &amp;nbsp;Initial Client is to be used when users are already on your network somewhere and have direct access to the Endpoint server (assuming you're not using the cloud service). &amp;nbsp;If your users are remote-only, then you need to send them a full package with the VPN site and feature blades pre-defined.&lt;/P&gt;
&lt;P&gt;When you do this, be sure you have a Software Deployment rule configured that will match the blades and components of the exported package; otherwise, when the client installs, the first thing it does is check the Software Deployment rules for any blade updates (install/remove blades) before it tries to load a policy. &amp;nbsp;This may result in multiple reboots while the client is trying to align itself with the server.&lt;/P&gt;
&lt;P&gt;Hope that helps!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2026 14:15:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Initial-client-including-VPN-site/m-p/277218#M11437</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2026-05-20T14:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Initial client including VPN site</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Initial-client-including-VPN-site/m-p/277268#M11440</link>
      <description>&lt;P&gt;The VPN Site configuration is inside of trac.config (C:\Program Files (x86)\CheckPoint\Endpoint Security\Endpoint Connect). You can copy that file to your new endpoints. Restart CP service&amp;nbsp;TracSrvWrapper (or better reboot machine) and you client is ready to connect.&lt;/P&gt;&lt;P&gt;If you open trac.config you see gibberish. To ungibberish edit trac_defaults, change "1" to "0" in the first line "OBSCURE_FILE". Restart&amp;nbsp;TracSrvWrapper and you see trac.config in cleartext.&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2026 10:05:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Initial-client-including-VPN-site/m-p/277268#M11440</guid>
      <dc:creator>morris</dc:creator>
      <dc:date>2026-05-21T10:05:17Z</dc:date>
    </item>
  </channel>
</rss>

