<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to deploy new VPN site details to Check Point Mobile client? in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-deploy-new-VPN-site-details-to-Check-Point/m-p/153424#M10646</link>
    <description>&lt;P&gt;E86.40 and above on Windows allows updating the VPN Site details via a push operation via the Harmony Endpoint web management.&amp;nbsp;&lt;BR /&gt;Mac support for this feature is planned for later in 2022.&amp;nbsp;&lt;BR /&gt;This is, to my knowledge, not supported for standalone VPN clients (i.e. not managed by Harmony Endpoint).&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/E86.40/EN/CP_E86.40_RemoteAccessClients_forWin_ReleaseNotes/Content/Topics/What-is-New.htm?Highlight=push" target="_blank"&gt;https://sc1.checkpoint.com/documents/E86.40/EN/CP_E86.40_RemoteAccessClients_forWin_ReleaseNotes/Content/Topics/What-is-New.htm?Highlight=push&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jul 2022 16:51:34 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-07-19T16:51:34Z</dc:date>
    <item>
      <title>Is it possible to deploy new VPN site details to Check Point Mobile client?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-deploy-new-VPN-site-details-to-Check-Point/m-p/82417#M10640</link>
      <description>&lt;P&gt;We have an existing deployment of Check Point Mobile for Windows clients.&lt;/P&gt;&lt;P&gt;When the clients were installed we manually configured the Site properties for each user.&lt;/P&gt;&lt;P&gt;We now want to add a second site to each client configuration (as a DR option if the main site is down).&lt;/P&gt;&lt;P&gt;Is it possible to push the additional site configuration to the clients when they next log in?&lt;/P&gt;&lt;P&gt;I haven't been able to find a reference/instructions for this.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Pedro&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2020 01:39:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-deploy-new-VPN-site-details-to-Check-Point/m-p/82417#M10640</guid>
      <dc:creator>Pedro_Silva</dc:creator>
      <dc:date>2020-04-20T01:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to deploy new VPN site details to Check Point Mobile client?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-deploy-new-VPN-site-details-to-Check-Point/m-p/82426#M10641</link>
      <description>&lt;P&gt;Yes, you should configure the site as a MEP gateway.&lt;BR /&gt;Then when the client connects again, it will get the information about the alternate site.&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_RemoteAccessVPN_AdminGuide/Content/Topics/137045.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_RemoteAccessVPN_AdminGuide/Content/Topics/137045.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2020 04:04:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-deploy-new-VPN-site-details-to-Check-Point/m-p/82426#M10641</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-20T04:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to deploy new VPN site details to Check Point Mobile client?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-deploy-new-VPN-site-details-to-Check-Point/m-p/82427#M10642</link>
      <description>Thanks but I think that link i to the wrong sk?</description>
      <pubDate>Mon, 20 Apr 2020 03:58:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-deploy-new-VPN-site-details-to-Check-Point/m-p/82427#M10642</guid>
      <dc:creator>Pedro_Silva</dc:creator>
      <dc:date>2020-04-20T03:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to deploy new VPN site details to Check Point Mobile client?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-deploy-new-VPN-site-details-to-Check-Point/m-p/82428#M10643</link>
      <description>Yes, I linked to an SK when I meant to link to the Remote Access VPN docs.&lt;BR /&gt;Changed my post above.</description>
      <pubDate>Mon, 20 Apr 2020 04:05:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-deploy-new-VPN-site-details-to-Check-Point/m-p/82428#M10643</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-20T04:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to deploy new VPN site details to Check Point Mobile client?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-deploy-new-VPN-site-details-to-Check-Point/m-p/82429#M10644</link>
      <description>&lt;P&gt;Thanks, I've found the configuration instructions.&lt;/P&gt;&lt;P&gt;I will give this a go when we next have a window where everyone isn't on the VPN at once.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2020 04:17:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-deploy-new-VPN-site-details-to-Check-Point/m-p/82429#M10644</guid>
      <dc:creator>Pedro_Silva</dc:creator>
      <dc:date>2020-04-20T04:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to deploy new VPN site details to Check Point Mobile client?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-deploy-new-VPN-site-details-to-Check-Point/m-p/83035#M10645</link>
      <description>&lt;P&gt;I have been reviewing the 80.20 Remote Access VPN Admin guide to try and understand MEP and I am confused about the best way to proceed.&lt;/P&gt;&lt;P&gt;We have a gateway at head office configured with Mobile Access and IP Sec VPN.&lt;/P&gt;&lt;P&gt;It provides Office mode address to Check Point Mobile for Windows clients. This is working fine.&lt;/P&gt;&lt;P&gt;We have now configured a new gateway at a second office. We want this to be used if the internet link at head office fails.&lt;/P&gt;&lt;P&gt;The offices are connected via a WAN link. The Remote Access VPN Domains overlap/are the same.&lt;/P&gt;&lt;P&gt;The moment the second gateway was up and configured we started to see some clients connect via it instead of head office.&lt;/P&gt;&lt;P&gt;I think this is Implicit - First to Respond at work.&lt;/P&gt;&lt;P&gt;Both gateways are configured for Visitor Mode.&lt;/P&gt;&lt;P&gt;I have tried disabling MEP but we are still seeing some clients connect via the second site.&lt;/P&gt;&lt;P&gt;"To disable MEP, set the following command to &lt;STRONG&gt;true&lt;/STRONG&gt; in &lt;STRONG&gt;DBedit&lt;/STRONG&gt;, the Check Point database tool:&lt;/P&gt;&lt;UL class="listbullet"&gt;&lt;LI&gt;desktop_disable_mep&lt;/LI&gt;&lt;LI&gt;When MEP is disabled, MEP RDP probing and fail over are not be performed. As a result, remote hosts connect to the Security Gateway defined without considering the MEP configuration. Remote Access clients use Visitor Mode instead of RDP to probe gateways."&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ideally I would prefer to set Primary-Backup but I am finding this next set of instructions regarding the backup gateway configuration confusing:&lt;/P&gt;&lt;P&gt;Primary-Backup&lt;/P&gt;&lt;P class="procedureheading"&gt;To configure Implicit Primary-Backup:&lt;/P&gt;&lt;OL class="listnumber"&gt;&lt;LI&gt;From Menu, click &lt;STRONG&gt;Global Properties&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;From the navigation tree, click &lt;STRONG&gt;VPN &amp;gt; Advanced&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Click &lt;STRONG&gt;Enable Backup &lt;/STRONG&gt;&lt;STRONG&gt;Gateway&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Click &lt;STRONG&gt;OK.&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Publish&lt;/STRONG&gt; the changes.&lt;/LI&gt;&lt;/OL&gt;&lt;P class="procedureheading"&gt;To configure the backup gateway settings:&lt;/P&gt;&lt;OL class="listnumber"&gt;&lt;LI&gt;Click &lt;STRONG&gt;Gateways &amp;amp; Servers&lt;/STRONG&gt; and double-click the primary Security Gateway.&lt;P class="listcontinue"&gt;The gateway window opens and shows the &lt;STRONG&gt;General Properties&lt;/STRONG&gt; page.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;From the navigation tree, click &lt;STRONG&gt;IPsec VPN&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Click &lt;STRONG&gt;Use Backup &lt;/STRONG&gt;&lt;STRONG&gt;Gateways&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;From the drop-down menu, select the backup gateway.&lt;/LI&gt;&lt;LI&gt;Determine if the backup gateway uses its own VPN domain.&lt;/LI&gt;&lt;LI&gt;To configure the backup gateway without a VPN domain of its own:&lt;OL class="listnumber2"&gt;&lt;LI&gt;Double-click the Security Gateway and from the navigation tree click &lt;STRONG&gt;Network Management &amp;gt; VPN Domain&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Click &lt;STRONG&gt;Manually defined&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Click the field and select the group or network that contains only the backup gateway&lt;/LI&gt;&lt;LI&gt;Click &lt;STRONG&gt;OK&lt;/STRONG&gt; and publish the changes.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;To configure the backup gateway that DOES have a VPN domain of its own:&lt;OL class="listnumber2"&gt;&lt;LI&gt;Make sure that the IP address of the backup gateway is not included in the VPN domain of the primary gateway.&lt;/LI&gt;&lt;LI&gt;For each backup gateway, define a VPN domain that does not overlap with the VPN domain of the other backup gateways.&lt;BR /&gt;&lt;BR /&gt;8. Configure IP pool NAT or Hide NAT to &lt;A title="Configuring Return Packets" href="https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RemoteAccessVPN_AdminGuide/164758.htm#o165244" target="_self"&gt;handle return packets&lt;/A&gt;.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;For our scenario, where the gateways are linked by an internal WAN and hence have the same overlapping VPN domain, do I use option 6 and select just the gateway object as the VPN domain on the backup gateway?&lt;/P&gt;&lt;P&gt;And if we are using Office Mode with an Office Mode range for each gateway with our internal routing configured can we ignore step 8 and remove NAT from Office mode?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Pedro&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2020 06:56:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-deploy-new-VPN-site-details-to-Check-Point/m-p/83035#M10645</guid>
      <dc:creator>Pedro_Silva</dc:creator>
      <dc:date>2020-04-24T06:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to deploy new VPN site details to Check Point Mobile client?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-deploy-new-VPN-site-details-to-Check-Point/m-p/153424#M10646</link>
      <description>&lt;P&gt;E86.40 and above on Windows allows updating the VPN Site details via a push operation via the Harmony Endpoint web management.&amp;nbsp;&lt;BR /&gt;Mac support for this feature is planned for later in 2022.&amp;nbsp;&lt;BR /&gt;This is, to my knowledge, not supported for standalone VPN clients (i.e. not managed by Harmony Endpoint).&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/E86.40/EN/CP_E86.40_RemoteAccessClients_forWin_ReleaseNotes/Content/Topics/What-is-New.htm?Highlight=push" target="_blank"&gt;https://sc1.checkpoint.com/documents/E86.40/EN/CP_E86.40_RemoteAccessClients_forWin_ReleaseNotes/Content/Topics/What-is-New.htm?Highlight=push&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2022 16:51:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-deploy-new-VPN-site-details-to-Check-Point/m-p/153424#M10646</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-07-19T16:51:34Z</dc:date>
    </item>
  </channel>
</rss>

