<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deployment of VPN site while fresh installation in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Deployment-of-VPN-site-while-fresh-installation/m-p/232823#M9657</link>
    <description>&lt;P&gt;For sure.&lt;/P&gt;&lt;P&gt;W&lt;/P&gt;&lt;P&gt;We use autopilot-managed devices via MS Intune (EntraID-registered), which are sent to employees. After their first login (via EntraID authentication), applications are deployed through MS Intune.&lt;/P&gt;&lt;P&gt;To deploy the Harmony client in MS Intune, we use the UEM integration provided by Check Point (see the screenshot in my first post). Once the initial client is installed, the deployment policy takes over, though there is currently no option to automatically configure a VPN site.&lt;/P&gt;&lt;P&gt;Using the MSI deployment (suggested by Leasly) isn't feasible, as we would need to update the package every time a new agent version is released. Since an external service provider manages this service, our Security department requires the flexibility to quickly choose which version is deployed. This is why we prefer using the deployment policy.&lt;BR /&gt;&lt;BR /&gt;Everything else is too&amp;nbsp;maintenance-intensive&lt;/P&gt;</description>
    <pubDate>Thu, 14 Nov 2024 22:28:16 GMT</pubDate>
    <dc:creator>CP-Shark</dc:creator>
    <dc:date>2024-11-14T22:28:16Z</dc:date>
    <item>
      <title>Deployment of VPN site while fresh installation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Deployment-of-VPN-site-while-fresh-installation/m-p/232809#M9653</link>
      <description>&lt;P&gt;Hello folks,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;we´ve set up a new way to install Harmony Endpoint client via MS Intune through UEM Integration:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="UEM.png" style="width: 389px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28467iF8900A99EF888B29/image-size/large?v=v2&amp;amp;px=999" role="button" title="UEM.png" alt="UEM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This works great. But how can a add our default VPN Site to this deployment? It can´t be the solution to add it manually or via "Push Operation".&lt;BR /&gt;&lt;BR /&gt;Any hints from the admins?&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;Oliver&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 21:46:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Deployment-of-VPN-site-while-fresh-installation/m-p/232809#M9653</guid>
      <dc:creator>CP-Shark</dc:creator>
      <dc:date>2024-11-14T21:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment of VPN site while fresh installation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Deployment-of-VPN-site-while-fresh-installation/m-p/232813#M9654</link>
      <description>&lt;P&gt;You need to create one package that contains all info you want to use. see it as a baseline.&lt;/P&gt;
&lt;P&gt;There are different ways to do this depending what you use.&lt;/P&gt;
&lt;P&gt;Here is an example:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-Common-for-HEP/Adding-New-VPN-Site-to-Exported-Package.htm#AddingNewPackagetoVPNSite" target="_blank"&gt;https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-Common-for-HEP/Adding-New-VPN-Site-to-Exported-Package.htm#AddingNewPackagetoVPNSite&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Or here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Deploying-Endpoint-Agent-using-Intune.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/Deploying-Endpoint-Agent-using-Intune.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;How to change from .exe to .msi -&amp;gt;&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk181442" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk181442&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 21:56:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Deployment-of-VPN-site-while-fresh-installation/m-p/232813#M9654</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-11-14T21:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment of VPN site while fresh installation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Deployment-of-VPN-site-while-fresh-installation/m-p/232815#M9655</link>
      <description>&lt;P&gt;Okay that´s not new to me.&lt;BR /&gt;&lt;BR /&gt;But we want to use the UEM integration for Intune followed by Software deployment policy.&amp;nbsp;&lt;BR /&gt;So I want a solution for that.&lt;BR /&gt;&lt;BR /&gt;The two solutions above needs to be updated everytime we decide to use a new endpoint agent version.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 22:02:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Deployment-of-VPN-site-while-fresh-installation/m-p/232815#M9655</guid>
      <dc:creator>CP-Shark</dc:creator>
      <dc:date>2024-11-14T22:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment of VPN site while fresh installation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Deployment-of-VPN-site-while-fresh-installation/m-p/232818#M9656</link>
      <description>&lt;P&gt;It might help us to understand if you can explain the expected workflow in more detail.&lt;BR /&gt;As far as I know, unless it's added to the MSI file, adding a VPN site requires a push operation.&lt;BR /&gt;If it's just updating an existing site, then that should occur the next time the user connects to the VPN&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 22:19:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Deployment-of-VPN-site-while-fresh-installation/m-p/232818#M9656</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-14T22:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment of VPN site while fresh installation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Deployment-of-VPN-site-while-fresh-installation/m-p/232823#M9657</link>
      <description>&lt;P&gt;For sure.&lt;/P&gt;&lt;P&gt;W&lt;/P&gt;&lt;P&gt;We use autopilot-managed devices via MS Intune (EntraID-registered), which are sent to employees. After their first login (via EntraID authentication), applications are deployed through MS Intune.&lt;/P&gt;&lt;P&gt;To deploy the Harmony client in MS Intune, we use the UEM integration provided by Check Point (see the screenshot in my first post). Once the initial client is installed, the deployment policy takes over, though there is currently no option to automatically configure a VPN site.&lt;/P&gt;&lt;P&gt;Using the MSI deployment (suggested by Leasly) isn't feasible, as we would need to update the package every time a new agent version is released. Since an external service provider manages this service, our Security department requires the flexibility to quickly choose which version is deployed. This is why we prefer using the deployment policy.&lt;BR /&gt;&lt;BR /&gt;Everything else is too&amp;nbsp;maintenance-intensive&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 22:28:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Deployment-of-VPN-site-while-fresh-installation/m-p/232823#M9657</guid>
      <dc:creator>CP-Shark</dc:creator>
      <dc:date>2024-11-14T22:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment of VPN site while fresh installation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Deployment-of-VPN-site-while-fresh-installation/m-p/232826#M9658</link>
      <description>&lt;P&gt;Possible this is an RFE.&lt;BR /&gt;Adding&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73549"&gt;@BarYassure&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 22:38:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Deployment-of-VPN-site-while-fresh-installation/m-p/232826#M9658</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-14T22:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment of VPN site while fresh installation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Deployment-of-VPN-site-while-fresh-installation/m-p/232827#M9659</link>
      <description>&lt;P&gt;Please tell me not there is no other solution for that.&lt;BR /&gt;This is such an obvious use case&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 22:41:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Deployment-of-VPN-site-while-fresh-installation/m-p/232827#M9659</guid>
      <dc:creator>CP-Shark</dc:creator>
      <dc:date>2024-11-14T22:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment of VPN site while fresh installation</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Deployment-of-VPN-site-while-fresh-installation/m-p/232830#M9660</link>
      <description>&lt;P&gt;What's not clear in what you've said so far is why a Push operation isn't an acceptable alternative.&lt;BR /&gt;The Push Operation can potentially be automated via an API call:&amp;nbsp;&lt;A href="https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.221#/AddVpnSiteParams" target="_blank"&gt;https://app.swaggerhub.com/apis/Check-Point/web-mgmt-external-api-production/1.9.221#/AddVpnSiteParams&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll admit, I'm not an Endpoint expert, so it's possible there is another way to do this.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 22:57:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Deployment-of-VPN-site-while-fresh-installation/m-p/232830#M9660</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-14T22:57:13Z</dc:date>
    </item>
  </channel>
</rss>

