<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: what is the purpose of disconnected policy? in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/205967#M8238</link>
    <description>&lt;P&gt;Hi thanks for the clarification around NLA - although this is for endpoint harmony cloud. How can the endpoint know its not on a corporate network if it has internet access and therefore can always reach the cloud instance? If we only want to impose restrictions when not connected to corporate resources this suggests that this would be when not connected to vpn(?)&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;How can I define all networks/services that are not trusted and disallow them in policy - but allow them if they are connected to a corporate environment.&lt;BR /&gt;&lt;BR /&gt;Apologies If Im misunderstanding.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Feb 2024 15:52:54 GMT</pubDate>
    <dc:creator>LazarusG</dc:creator>
    <dc:date>2024-02-13T15:52:54Z</dc:date>
    <item>
      <title>what is the purpose of disconnected policy?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/205901#M8234</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I hope you can help.&lt;/P&gt;&lt;P&gt;We have a requirement to prevent users on non-corporate networks from copying data to network devices such as a NAS - so this is network traffic not port protection and I guess it would fall under the firewall blade(?)&lt;/P&gt;&lt;P&gt;I was thinking I could use the disconnected policy (not defined by default) however the definition in the harmony manual is (paraphrased) 'Disconnected state rule is enforced when an endpoint computer is not connected to the Harmony Endpoint Security Mangement server - eg you can enforce a more restrictive policy if users are working from home and are not protected by organizational resources'&lt;/P&gt;&lt;P&gt;However, this suggests that the endpoint doesn't have internet access if it can't reach the cloud portal(?)&lt;/P&gt;&lt;P&gt;Is the disconnected policy a correct use case here? If so are there any examples of how to set it up (I dont seem to be able to find any). Would I have to define all corp networks as objects in the trust zone so that anything else is by&amp;nbsp;default in the internet zone object?&lt;/P&gt;&lt;P&gt;If I want to limit access when not connected to corp resources would network location awareness be a more appropriate feature?&lt;/P&gt;&lt;P&gt;Many Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 11:24:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/205901#M8234</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2024-02-13T11:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: what is the purpose of disconnected policy?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/205908#M8235</link>
      <description>&lt;P&gt;Specifics aside for the moment the use case you describe is typically where the EPM is on-prem and perhaps only contactable by VPN or similar.&lt;/P&gt;
&lt;P&gt;Location awareness is often more about determining under what conditions a VPN connection should be attempted.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 12:05:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/205908#M8235</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-02-13T12:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: what is the purpose of disconnected policy?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/205921#M8236</link>
      <description>&lt;P&gt;I think you misunderstand the meaning of the policy. Let's see how it is defined &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_HarmonyEndpointWebManagement_AdminGuide/Content/Topics-Common-for-HEP/Connected-Disconnected-Restricted-Rules.htm" target="_self"&gt;in the admin guide&lt;/A&gt;:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;&lt;SPAN class="Menu_Options"&gt;Disconnected&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;state rule is enforced when an endpoint computer is not connected to the Harmony Endpoint&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" style="font-family: inherit; background-color: #ffffff;" role="button" href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_HarmonyEndpointWebManagement_AdminGuide/Content/Topics-Common-for-HEP/Connected-Disconnected-Restricted-Rules.htm#" target="_blank" rel="noopener" data-mc-state="closed" data-aria-describedby="31a7f5cd-ea8f-4a50-9878-215aeeeb428f"&gt;Security Management Server&lt;/A&gt;.&amp;nbsp;&lt;SPAN&gt;For example, you can enforce a more restrictive policy if users are working from home and are not protected by organizational resources. You can define a&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Disconnected policy&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;for only some of the&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Endpoint_SandBlast.tp_eps variable"&gt;Endpoint Security&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;components.&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;Then, there is an example of how functionalities can be defined:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="_Val__1-1707831390860.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24477iCA14B9446A8943DC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="_Val__1-1707831390860.png" alt="_Val__1-1707831390860.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;It is up to you how to define the FW rules in the disconnected policy, and if you believe Internet connectivity should be allowed, you can do that.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 13:39:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/205921#M8236</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-02-13T13:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: what is the purpose of disconnected policy?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/205932#M8237</link>
      <description>&lt;P&gt;Pretty much what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;said is what TAC provided us while back.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 14:05:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/205932#M8237</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-13T14:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: what is the purpose of disconnected policy?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/205967#M8238</link>
      <description>&lt;P&gt;Hi thanks for the clarification around NLA - although this is for endpoint harmony cloud. How can the endpoint know its not on a corporate network if it has internet access and therefore can always reach the cloud instance? If we only want to impose restrictions when not connected to corporate resources this suggests that this would be when not connected to vpn(?)&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;How can I define all networks/services that are not trusted and disallow them in policy - but allow them if they are connected to a corporate environment.&lt;BR /&gt;&lt;BR /&gt;Apologies If Im misunderstanding.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 15:52:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/205967#M8238</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2024-02-13T15:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: what is the purpose of disconnected policy?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/205973#M8239</link>
      <description>&lt;P&gt;client settings &amp;gt; general&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="firefox_rZgKAPPlBm.png" style="width: 523px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24485iD8FF16B7526A9DF7/image-size/large?v=v2&amp;amp;px=999" role="button" title="firefox_rZgKAPPlBm.png" alt="firefox_rZgKAPPlBm.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 16:02:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/205973#M8239</guid>
      <dc:creator>Machine_Head</dc:creator>
      <dc:date>2024-02-13T16:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: what is the purpose of disconnected policy?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/205975#M8240</link>
      <description>&lt;P&gt;nice! thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 16:26:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/205975#M8240</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2024-02-13T16:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: what is the purpose of disconnected policy?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/206035#M8244</link>
      <description>&lt;P&gt;It would still be nice to have some kind of an example offline/disconnected policy in documentation or the manual. Our customer says they had this when they had an on-prem Endpoint server, Now they have ben challenged by auditors to prove offline file copies are not allowed and nothing exists in the portal. I'm uncertain how to go about constructing it.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 09:29:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/206035#M8244</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2024-02-14T09:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: what is the purpose of disconnected policy?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/206062#M8245</link>
      <description>&lt;P&gt;I agree, it would be beneficial.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 12:18:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/what-is-the-purpose-of-disconnected-policy/m-p/206062#M8245</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-14T12:18:29Z</dc:date>
    </item>
  </channel>
</rss>

