<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block Internet when disconnecting VPN in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100318#M2720</link>
    <description>&lt;P&gt;Curious why you don't want to use the Desktop Firewall to do this?&lt;/P&gt;</description>
    <pubDate>Wed, 28 Oct 2020 02:46:06 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-10-28T02:46:06Z</dc:date>
    <item>
      <title>Block Internet when disconnecting VPN</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100269#M2719</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We try to block Internet when user are not connecting to VPN from external network. It works fine with standalone VPN client. However, when we recently deployed Endpoint Security client, things got messed up. We tried to use Endpoint Security policy for the OS firewall in EPS. With this EPS policy being used, we cannot block Internet when user not connecting VPN. In order to block Internet, we have to enforce desktop policy to OS firewall.&lt;/P&gt;&lt;P&gt;Is there a way to use EPS policy but still be able to block Internet access when VPN not being connected?&lt;/P&gt;&lt;P&gt;Many Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 15:40:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100269#M2719</guid>
      <dc:creator>littlewood</dc:creator>
      <dc:date>2020-10-27T15:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: Block Internet when disconnecting VPN</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100318#M2720</link>
      <description>&lt;P&gt;Curious why you don't want to use the Desktop Firewall to do this?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 02:46:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100318#M2720</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-28T02:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: Block Internet when disconnecting VPN</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100391#M2721</link>
      <description>&lt;P&gt;Sorry PhoneBoy, I didn't get your question. When you said Desktop firewall, did you mean the windows firewall or the EPS firewall with enforced desktop policy?&lt;/P&gt;&lt;P&gt;Before we implemented EPS, we didn't use OS level firewall on workstations / servers. Only the VPN clients had desktop policy applied which kind of worked as an OS firewall.&lt;BR /&gt;Now, we decided to use EPS firewall because we were told it was more functional, more granular and easier to manage comparing to desktop policy.&lt;BR /&gt;However, when we enforced Endpoint security policy to EPS firewall, the VPN cannot block accessing Internet via the other interfaces anymore. I guess, the VPN might need the desktop policy to block the Internet. But if we applied the desktop policy, we cannot use Endpoint Security firewall.&lt;BR /&gt;The other reason we don't want to use desktop policy for all the workstations is that our desktop policy blocks the multicast traffic. We need to access multicast traffic to view the live video on our surveillance system.&lt;/P&gt;&lt;P&gt;Hope I properly answered your question. We just want to restrict that the Internet only go through VPN tunnel. If you know how to do it through VPN or OS firewall, that would be great.&lt;/P&gt;&lt;P&gt;Many thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 14:27:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100391#M2721</guid>
      <dc:creator>littlewood</dc:creator>
      <dc:date>2020-10-28T14:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Block Internet when disconnecting VPN</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100394#M2723</link>
      <description>&lt;P&gt;I mean the EPS firewall with enforced desktop policy.&lt;BR /&gt;You should be able to configure the desktop policy to permit multicast.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 14:35:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100394#M2723</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-28T14:35:20Z</dc:date>
    </item>
    <item>
      <title>Re: Block Internet when disconnecting VPN</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100402#M2724</link>
      <description>&lt;P&gt;1. Desktop policy will bring gateway rules into local firewall. That's one thing I don't want it to happen.&lt;/P&gt;&lt;P&gt;For example, the rule blocking multicast is actually located in gateway instead of directly in desktop policy.&lt;/P&gt;&lt;P&gt;If I use desktop policy, to allow the multicast traffic to go through OS firewall, I have to change the rule on gateway. But we don't want to multicast traffic cross gateway.&lt;/P&gt;&lt;P&gt;2. The other reason we prefer to Endpoint security policy is that as I said it's easier, more functional and more granular.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, we want to make different rules for different computers. It's very easy in smart endpoint console. Just create virtual groups and sign the different policies to them. Add the computers to different virtual groups.&lt;/P&gt;&lt;P&gt;Not sure how to do it in desktop policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea to use Endpoint policy and make the Internet only go through VPN?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 15:21:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100402#M2724</guid>
      <dc:creator>littlewood</dc:creator>
      <dc:date>2020-10-28T15:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: Block Internet when disconnecting VPN</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100620#M2728</link>
      <description>&lt;P&gt;Actually, you can configure a Desktop Policy in a completely separate layer on the gateway.&lt;BR /&gt;You just have to enable the Policy Server on the relevant gateway and add the Desktop policy to the relevant package.&lt;BR /&gt;Also, multicast will never cross a gateway unless you configure PIM, even if there is a rule in the policy that allows it.&lt;/P&gt;
&lt;P&gt;But, you should be able to do this on the Endpoint side as well in, like you said, a more granular way.&lt;BR /&gt;For multicast, in the relevant policy, create a rule like below:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-10-29 at 6.11.41 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8708i31F7FAD9F3CFD893/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-10-29 at 6.11.41 PM.png" alt="Screen Shot 2020-10-29 at 6.11.41 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The multicast-net is a network object I created (network 224.0.0.0 mask 224.0.0.0).&lt;BR /&gt;You can add this rule to the relevant policy.&lt;/P&gt;
&lt;P&gt;Further, you can create a different firewall policy that is used when the client is disconnected.&amp;nbsp;&lt;BR /&gt;It's just a matter of cloning the relevant Endpoint rule, setting the enforcement state to Disconnected, and modifying the policy as appropriate.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-10-29 at 6.19.02 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8709i8C3D64FFDFB49311/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-10-29 at 6.19.02 PM.png" alt="Screen Shot 2020-10-29 at 6.19.02 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 01:20:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100620#M2728</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-30T01:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: Block Internet when disconnecting VPN</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100668#M2730</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;When I using Endpoint policy, I don't worry about multicast. The multicast is only a problem when we using desktop policy.&lt;/P&gt;&lt;P&gt;One the Endpoint side, the issue is that I can't lock down Internet with Endpoint policy.&lt;/P&gt;&lt;P&gt;We tried the disconnected policy, however, we are using cloud Endpoint policy server. Even we disconnect VPN, the client is still connected to policy server.&lt;/P&gt;&lt;P&gt;So we can't use it to lock down Internet.&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 13:51:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100668#M2730</guid>
      <dc:creator>littlewood</dc:creator>
      <dc:date>2020-10-30T13:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: Block Internet when disconnecting VPN</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100700#M2731</link>
      <description>&lt;P&gt;Yeah, that is an issue, since you will always have connectivity to the Endpoint Management Server.&lt;BR /&gt;I suspect the answer will be to use the Desktop policy instead of the one from Endpoint.&lt;BR /&gt;A TAC case is probably in order.&lt;/P&gt;</description>
      <pubDate>Sat, 31 Oct 2020 00:53:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100700#M2731</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-31T00:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: Block Internet when disconnecting VPN</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100946#M2735</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;Is it possible to combine compliance policy and end point policy to achieve it?&lt;/P&gt;&lt;P&gt;Like using compliance policy to detect if VPN connected. If no, let end point policy block the network.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 22:28:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Block-Internet-when-disconnecting-VPN/m-p/100946#M2735</guid>
      <dc:creator>littlewood</dc:creator>
      <dc:date>2020-11-02T22:28:25Z</dc:date>
    </item>
  </channel>
</rss>

