<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prohibit Capsule and Mobile access connections for Apple devices only. in Mobile</title>
    <link>https://community.checkpoint.com/t5/Mobile/Prohibit-Capsule-and-Mobile-access-connections-for-Apple-devices/m-p/195052#M1040</link>
    <description>&lt;P&gt;This field was not modified and the default value was used:&lt;BR /&gt;active_vendor (Fiberlink)&lt;/P&gt;</description>
    <pubDate>Fri, 13 Oct 2023 12:20:48 GMT</pubDate>
    <dc:creator>mirnick</dc:creator>
    <dc:date>2023-10-13T12:20:48Z</dc:date>
    <item>
      <title>Prohibit Capsule and Mobile access connections for Apple devices only.</title>
      <link>https://community.checkpoint.com/t5/Mobile/Prohibit-Capsule-and-Mobile-access-connections-for-Apple-devices/m-p/194916#M1036</link>
      <description>&lt;P&gt;Can you please tell me if there is a way to restrict access and reset RemoteAcceses connections from Apple hardware?&lt;BR /&gt;I need to disable connections to Capsule and Mobile access only for Apple devices (MacBook and iPhone - iOS, macOS) and leave access from other devices, including Android.&lt;BR /&gt;The following solutions were found:&lt;BR /&gt;1. SCV check. But this method as far as I know does not work on macOS and is intended only for Windows devices.&lt;BR /&gt;2. Using the Compliance blade. Compliance on macos is the Compliance blade in Harmony Endpoint. Compliance on ios/android is Harmony Mobile. However. we do not have any Harmony products available.&lt;BR /&gt;3. Mobile Device Management (MDM). As a result of testing the solution described in sk107207, I was unable to correctly block connections from Apple devices only. Perhaps someone has had experience in configuring this method.&lt;BR /&gt;&lt;BR /&gt;Please advise if it is possible to organize this restriction in Checkpoint? Perhaps this restriction can be implemented using mac-addresses in some way, but I have not been able to find something suitable.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 09:19:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Prohibit-Capsule-and-Mobile-access-connections-for-Apple-devices/m-p/194916#M1036</guid>
      <dc:creator>mirnick</dc:creator>
      <dc:date>2023-10-12T09:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: Prohibit Capsule and Mobile access connections for Apple devices only.</title>
      <link>https://community.checkpoint.com/t5/Mobile/Prohibit-Capsule-and-Mobile-access-connections-for-Apple-devices/m-p/194969#M1037</link>
      <description>&lt;P&gt;Have you configured MDM Cooperative Enforcement per:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk98201" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk98201&lt;/A&gt;?&lt;BR /&gt;Otherwise, sk107207 won't work.&lt;/P&gt;
&lt;P&gt;I don't believe there is another option at present.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Oct 2023 17:10:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Prohibit-Capsule-and-Mobile-access-connections-for-Apple-devices/m-p/194969#M1037</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-12T17:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: Prohibit Capsule and Mobile access connections for Apple devices only.</title>
      <link>https://community.checkpoint.com/t5/Mobile/Prohibit-Capsule-and-Mobile-access-connections-for-Apple-devices/m-p/195014#M1038</link>
      <description>&lt;P&gt;Yes, in order for this sk to work, I initially performed the following global options:&lt;BR /&gt;enabled - 1&lt;BR /&gt;monitor_only - 0&lt;BR /&gt;fail_open - I tried to use both 1 and 0.&lt;/P&gt;&lt;P&gt;However, I was not able to block connections only from Apple devices and all devices were blocked or allowed.&lt;BR /&gt;Could you please tell me if you have any experience in configuring MDM?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 07:25:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Prohibit-Capsule-and-Mobile-access-connections-for-Apple-devices/m-p/195014#M1038</guid>
      <dc:creator>mirnick</dc:creator>
      <dc:date>2023-10-13T07:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: Prohibit Capsule and Mobile access connections for Apple devices only.</title>
      <link>https://community.checkpoint.com/t5/Mobile/Prohibit-Capsule-and-Mobile-access-connections-for-Apple-devices/m-p/195017#M1039</link>
      <description>&lt;P&gt;Which MDM do you use ?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 08:58:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Prohibit-Capsule-and-Mobile-access-connections-for-Apple-devices/m-p/195017#M1039</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-10-13T08:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: Prohibit Capsule and Mobile access connections for Apple devices only.</title>
      <link>https://community.checkpoint.com/t5/Mobile/Prohibit-Capsule-and-Mobile-access-connections-for-Apple-devices/m-p/195052#M1040</link>
      <description>&lt;P&gt;This field was not modified and the default value was used:&lt;BR /&gt;active_vendor (Fiberlink)&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 12:20:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Prohibit-Capsule-and-Mobile-access-connections-for-Apple-devices/m-p/195052#M1040</guid>
      <dc:creator>mirnick</dc:creator>
      <dc:date>2023-10-13T12:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: Prohibit Capsule and Mobile access connections for Apple devices only.</title>
      <link>https://community.checkpoint.com/t5/Mobile/Prohibit-Capsule-and-Mobile-access-connections-for-Apple-devices/m-p/195059#M1041</link>
      <description>&lt;P&gt;You can not use it without MDM.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 12:57:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Prohibit-Capsule-and-Mobile-access-connections-for-Apple-devices/m-p/195059#M1041</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-10-13T12:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: Prohibit Capsule and Mobile access connections for Apple devices only.</title>
      <link>https://community.checkpoint.com/t5/Mobile/Prohibit-Capsule-and-Mobile-access-connections-for-Apple-devices/m-p/195138#M1042</link>
      <description>&lt;P&gt;The feature in question is called MDM Cooperative Enforcement.&lt;BR /&gt;It requires the use of a &lt;A href="https://www.checkpoint.com/cyber-hub/threat-prevention/what-is-mdm/" target="_self"&gt;Mobile Device Management&lt;/A&gt; solution.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk98201" target="_self"&gt;From the SK&lt;/A&gt;:&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;The Mobile Device Management (MDM) cooperative enforcement feature allows integration of Check Point Mobile VPN clients (Check Point Capsule Workspace, Check Point Capsule VPN, Check Point Capsule Connect) with third party MDM vendors. When the feature is enabled and properly configured - only devices that comply with a (third-party) MDM vendor’s policy will be allowed to connect to a Remote Access gateway. The benefit of this feature is increased security, preventing non-compliant, and potentially security-compromised mobile devices from accessing company resources over VPN.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 21:57:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Mobile/Prohibit-Capsule-and-Mobile-access-connections-for-Apple-devices/m-p/195138#M1042</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-13T21:57:51Z</dc:date>
    </item>
  </channel>
</rss>

