<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Harmony Endpoint/Connet vs SASE in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Connet-vs-SASE/m-p/118450#M4331</link>
    <description>&lt;P&gt;We are about to GA Harmony Connect.&lt;BR /&gt;Right now I don’t believe you can route traffic from client to cloud to DC.&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/332"&gt;@Tomer_Sole&lt;/a&gt;&amp;nbsp;will have to comment on roadmap for that.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For Harmony Endpoint, host-based Auth involves using R80.40+ and machine certificates.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121173&amp;amp;partition=Basic&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121173&amp;amp;partition=Basic&amp;amp;product=Quantum&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Always-Connect feature can be configured to be enabled/disabled&amp;nbsp;in SmartConsole &amp;gt; Global Properties &amp;gt; Remote Access &amp;gt; Endpoint Connect &amp;gt; 'Connect mode'.&lt;BR /&gt;It is then enforced on all the clients that connect to the site.&lt;/P&gt;</description>
    <pubDate>Sun, 16 May 2021 05:06:02 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-05-16T05:06:02Z</dc:date>
    <item>
      <title>Harmony Endpoint/Connet vs SASE</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Connet-vs-SASE/m-p/118236#M4316</link>
      <description>&lt;DIV&gt;1. How we can implement the SASE solution with Harmony&amp;nbsp;- can we with Harmony Connect or Harmony Endpoint?&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;2. Is it possible to do with Harmony Endpoint/Connect or just with "Conventional" Endpoint?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Can we implement the following features:&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;Compliance Policy&lt;/STRONG&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;Replace current SCV checks with Harmony Endpoint compliance checks&lt;/LI&gt;&lt;LI&gt;Configure compliance policy (Domain, patching, certificates, etc)&lt;/LI&gt;&lt;LI&gt;Test compliance policy and update where necessary&lt;/LI&gt;&lt;LI&gt;Document compliance policy settings&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;Endpoint Firewall&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Use cases: Location awareness, IT remote administration of endpoints (User or IP address based inbound rules), administration of endpoint firewall, etc&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Remote Access VPN Policy&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Setup Harmony Endpoint policy for VPN sites&lt;/LI&gt;&lt;LI&gt;Setup certificate (host-based authentication) always-on VPN. In addition or replaces current MFA (User-based authentication)?&lt;/LI&gt;&lt;LI&gt;Pre-authentication to Active Directory configured via policy&lt;/LI&gt;&lt;LI&gt;Setup DHCP Infoblox configuration for VPN clients&lt;/LI&gt;&lt;LI&gt;VPN re-establishes after the laptop has been in sleep mode&lt;/LI&gt;&lt;LI&gt;Configure VPN to not connect when the laptop is at Corporate campuses&lt;/LI&gt;&lt;LI&gt;Configure and test visitor mode functions as expected&lt;/LI&gt;&lt;LI&gt;VPN will be split tunnel&lt;/LI&gt;&lt;LI&gt;Prevent laptops from connecting to the VPN (lost, stolen, employee leaves the company)&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 12 May 2021 12:45:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Connet-vs-SASE/m-p/118236#M4316</guid>
      <dc:creator>Michael_Rolbin</dc:creator>
      <dc:date>2021-05-12T12:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Endpoint/Connet vs SASE</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Connet-vs-SASE/m-p/118420#M4327</link>
      <description>&lt;P&gt;You can run Harmony Connect and Harmony Endpoint on the same PC, FYI, but they're really complimentary solutions that solve somewhat different problems.&lt;/P&gt;
&lt;P&gt;All of the requirements you list are mostly done with Harmony Endpoint (new name for SandBlast Agent and friends).&lt;BR /&gt;Where Harmony Connect comes in handy is in the situation where you'd normally route Internet traffic back to your datacenter for visibility/security reasons.&lt;BR /&gt;Instead of doing that, traffic is secured/inspected in the cloud.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 21:44:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Connet-vs-SASE/m-p/118420#M4327</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-14T21:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Endpoint/Connet vs SASE</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Connet-vs-SASE/m-p/118449#M4330</link>
      <description>&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;Some missing points for me:&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Lack of Harmony Connect documentation related to SASE. I found the Betta version is available but cannot find any instructions on how to configure connections from Endpoints via Harmony Cloud to DCs - the classic SASE architecture.&lt;/P&gt;&lt;P&gt;2. How to assign&amp;nbsp;&lt;SPAN&gt;a certificate (host-based authentication) always-on VPN and policy per VPN site.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 16 May 2021 04:25:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Connet-vs-SASE/m-p/118449#M4330</guid>
      <dc:creator>Michael_Rolbin</dc:creator>
      <dc:date>2021-05-16T04:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Endpoint/Connet vs SASE</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Connet-vs-SASE/m-p/118450#M4331</link>
      <description>&lt;P&gt;We are about to GA Harmony Connect.&lt;BR /&gt;Right now I don’t believe you can route traffic from client to cloud to DC.&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/332"&gt;@Tomer_Sole&lt;/a&gt;&amp;nbsp;will have to comment on roadmap for that.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For Harmony Endpoint, host-based Auth involves using R80.40+ and machine certificates.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121173&amp;amp;partition=Basic&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121173&amp;amp;partition=Basic&amp;amp;product=Quantum&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Always-Connect feature can be configured to be enabled/disabled&amp;nbsp;in SmartConsole &amp;gt; Global Properties &amp;gt; Remote Access &amp;gt; Endpoint Connect &amp;gt; 'Connect mode'.&lt;BR /&gt;It is then enforced on all the clients that connect to the site.&lt;/P&gt;</description>
      <pubDate>Sun, 16 May 2021 05:06:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Connet-vs-SASE/m-p/118450#M4331</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-16T05:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Endpoint/Connet vs SASE</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Connet-vs-SASE/m-p/275647#M11406</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/993"&gt;@Michael_Rolbin&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;I was wondering if you have achieved all of the following using the Harmony Endpoint. We have similar requirements and need to use Harmony Endpoint:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;VPN automatically re-establishes after the laptop wakes from sleep&lt;/LI&gt;&lt;LI&gt;VPN does not connect when the laptop is on corporate campuses&lt;/LI&gt;&lt;LI&gt;VPN automatically connects when the laptop is outside the corporate network&lt;/LI&gt;&lt;LI&gt;When outside the corporate campus and the VPN is not connected, internet access is blocked except for a few specific URLs&lt;/LI&gt;&lt;/OL&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 16 Apr 2026 23:45:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Connet-vs-SASE/m-p/275647#M11406</guid>
      <dc:creator>Cathy_Cheng</dc:creator>
      <dc:date>2026-04-16T23:45:34Z</dc:date>
    </item>
  </channel>
</rss>

