<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Deploy list of VPN sites for macOS in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237278#M9899</link>
    <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I am trying to deploy a list of VPN sites that users can choose from, along with the CheckPoint client on all our company Macs.&lt;BR /&gt;Is there any documentation that describes how to do that?&lt;BR /&gt;&lt;BR /&gt;As far as I understood, the trac.config file needs to be edited adding the details of each vpn site, but how is that done? Is there a specific console?&lt;BR /&gt;&lt;BR /&gt;Thank you.&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 31 Dec 2024 08:26:47 GMT</pubDate>
    <dc:creator>IWildcard</dc:creator>
    <dc:date>2024-12-31T08:26:47Z</dc:date>
    <item>
      <title>Deploy list of VPN sites for macOS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237278#M9899</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I am trying to deploy a list of VPN sites that users can choose from, along with the CheckPoint client on all our company Macs.&lt;BR /&gt;Is there any documentation that describes how to do that?&lt;BR /&gt;&lt;BR /&gt;As far as I understood, the trac.config file needs to be edited adding the details of each vpn site, but how is that done? Is there a specific console?&lt;BR /&gt;&lt;BR /&gt;Thank you.&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2024 08:26:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237278#M9899</guid>
      <dc:creator>IWildcard</dc:creator>
      <dc:date>2024-12-31T08:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: Deploy list of VPN sites for macOS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237339#M9900</link>
      <description>&lt;P&gt;The best way to “edit” trac.config file is to use the client to configure the required sites, then distribute trac.config.&lt;BR /&gt;On Windows at least this trac.config can be bundled into the installer.&lt;BR /&gt;Believe this is also possible on the Mac, but I’m not certain of the exact steps.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2024 17:33:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237339#M9900</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-31T17:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: Deploy list of VPN sites for macOS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237347#M9901</link>
      <description>&lt;P&gt;Is this what you are looking for?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_RemoteAccessVPN_AdminGuide/Topics-VPNRG/MEP.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_RemoteAccessVPN_AdminGuide/Topics-VPNRG/MEP.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2024 19:09:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237347#M9901</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-31T19:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Deploy list of VPN sites for macOS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237447#M9904</link>
      <description>&lt;P class=""&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;,&lt;/P&gt;&lt;P class=""&gt;Just to clarify, are you suggesting that I set up all the VPN sites that we need to push to the CheckPoint client on a test Mac, then export the final trac.config file and distribute it to all devices?&lt;BR /&gt;I have tried this, and it appears to work well.&lt;BR /&gt;&lt;BR /&gt;However, I’m facing another issue and would appreciate your assistance with it:&lt;BR /&gt;Occasionally, we need to add or remove VPN sites and deploy the updated trac.config file to our Macs.&lt;BR /&gt;I followed the same procedure, added a couple of VPN sites, and attempted to distribute the updated file. However, when trying to replace the trac.config file on Macs that already had the client installed, I encountered an issue where the file could not be replaced.&lt;BR /&gt;What's the correct way to stop the service before deploying the updated trac.config file to ensure the replacement goes smoothly?&lt;BR /&gt;&lt;BR /&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 16:28:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237447#M9904</guid>
      <dc:creator>IWildcard</dc:creator>
      <dc:date>2025-01-02T16:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: Deploy list of VPN sites for macOS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237452#M9905</link>
      <description>&lt;P&gt;Yes, you have it correct, and yes you need to stop/start the relevant service to replace trac.config on a system with the VPN client running/installed.&lt;BR /&gt;The two commands to do this are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;sudo launchctl stop com.checkpoint.epc.service&lt;/LI&gt;
&lt;LI&gt;sudo launchctl start com.checkpoint.epc.service&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 02 Jan 2025 18:51:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237452#M9905</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-02T18:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: Deploy list of VPN sites for macOS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237502#M9908</link>
      <description>&lt;P&gt;Thank you for the quick reply&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;.&lt;BR /&gt;&lt;BR /&gt;The commands that you mentioned in your previous message seem to work for stopping the vpn service (I was connected when I launched the first command, and got immediately disconnected).&lt;BR /&gt;However, I was still unable to replace the trac.config file in the folder /Library/Application Support/Checkpoint/Endpoint Security/Endpoint Connect, receiving an error message saying that the operation was not permitted.&lt;BR /&gt;My assumption is that the file is still locked by another CheckPoint service on the device.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 10:47:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237502#M9908</guid>
      <dc:creator>IWildcard</dc:creator>
      <dc:date>2025-01-03T10:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: Deploy list of VPN sites for macOS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237565#M9910</link>
      <description>&lt;P&gt;It could very well be.&lt;BR /&gt;Another possibility is to use the "trac" binary (in the same location as trac.config) to add the sites via the CLI (e.g. with trac create).&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 19:36:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237565#M9910</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-03T19:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: Deploy list of VPN sites for macOS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237943#M9914</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Is it possible to know which are the&amp;nbsp;&lt;SPAN&gt;CheckPoint services that lock the trac.config file, and if they can be stopped so the file can be replaced without having to uninstall the client and re-install it with the new trac.config file, which is not really an ideal workflow?&lt;BR /&gt;&lt;BR /&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 09:58:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237943#M9914</guid>
      <dc:creator>IWildcard</dc:creator>
      <dc:date>2025-01-08T09:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: Deploy list of VPN sites for macOS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237965#M9916</link>
      <description>&lt;P&gt;If you select Shutdown Client from tray menue this should work using local admin rights - at least for the RA VPN only EP client i use. If you use the Harmony EPS blades it would be more difficult...&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 12:20:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/237965#M9916</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-01-08T12:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: Deploy list of VPN sites for macOS</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/238026#M9917</link>
      <description>&lt;P&gt;The only service that needs it is the "epc" service.&lt;BR /&gt;I imagine the file is locked as a result of Harmony Endpoint self-protection features.&lt;BR /&gt;Not sure these can be disabled,&amp;nbsp; but you should confirm with TAC.&lt;/P&gt;
&lt;P&gt;Have you tried creating the site using the "trac" binary I mentioned above?&lt;BR /&gt;For example to create a site from the gateway at 192.0.2.54 and naming it "MyVPNSite" in the UI, you issue the following command:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;"/Library/Application Support/Checkpoint/Endpoint Security/Endpoint Connect/trac" create -s 192.0.2.254 -di MyVPNSite&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Assuming you have some sort of remote execution capability on the Endpoints, this might be easier.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 23:50:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Deploy-list-of-VPN-sites-for-macOS/m-p/238026#M9917</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-08T23:50:50Z</dc:date>
    </item>
  </channel>
</rss>

