<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Compliance blade Endpoint security client in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-blade-Endpoint-security-client/m-p/236440#M2710</link>
    <description>&lt;P&gt;Have you configured any of the settings here?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28940i3F16A56D5E84A51A/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Dec 2024 21:15:11 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-12-19T21:15:11Z</dc:date>
    <item>
      <title>Compliance blade Endpoint security client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-blade-Endpoint-security-client/m-p/236065#M2707</link>
      <description>&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;I try to configure Compliance Policy for remote access VPN clients (endpoint security) in my LAB network, and have some troubles with this. My lab: Checkpoint Cluster 81.10 , JHF take 170&lt;/P&gt;&lt;P&gt;I create Compliance policy, where define, for what users this policy must work. In this policy i check Antivirus (McAffee for test), and set Action "Restrict" , if client machine don't have Antivirus McAffee.&lt;/P&gt;&lt;P&gt;Ok, after that i create endpoint client package, deploy it to client machine, install, and try to check, how it's work.&lt;/P&gt;&lt;P&gt;But.. It's not work..&lt;/P&gt;&lt;P&gt;What i have now:&lt;/P&gt;&lt;P&gt;Endpoint Client connect to CP by VPN (it's work!)&lt;/P&gt;&lt;P&gt;Client had check for compliance (for enabled blades). After i see, that client not compliante, because don't have McAffee AV. And after 5 minutes (5 heartbeat * 60 seconds), client change state to Restricted.&lt;/P&gt;&lt;P&gt;But!&lt;/P&gt;&lt;P&gt;Client still has access to internal network!! And after 5 minutes and after 10 minutes and so on&lt;/P&gt;&lt;P&gt;Nobody change, the internal network remains available.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What i did incorrectly?&lt;/P&gt;&lt;P&gt;I check documectation , and found that (in Harmony Endpoint Administration guide &lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-Common-for-HEP/Connected-Disconnected-Restricted-Rules.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-Common-for-HEP/Connected-Disconnected-Restricted-Rules.htm&lt;/A&gt;)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;Restricted&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;state rule is enforced when an endpoint computer is not in compliance with the enterprise security requirements. In this state, you usually choose to prevent users from accessing some, if not all, network resources. &lt;STRONG&gt;You can define a&lt;EM&gt;&amp;nbsp;Restricted policy&lt;/EM&gt;&amp;nbsp;for only some of the&amp;nbsp;&lt;SPAN class=""&gt;Endpoint Security&lt;/SPAN&gt;&amp;nbsp;components&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Where Compliance don't have Restricted actions.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is this mean, that Restricted Action don't work for Compliance Rules??&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I hope somebody can explain me, how it work..&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 17:13:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-blade-Endpoint-security-client/m-p/236065#M2707</guid>
      <dc:creator>ajax</dc:creator>
      <dc:date>2024-12-17T17:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: Compliance blade Endpoint security client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-blade-Endpoint-security-client/m-p/236074#M2708</link>
      <description>&lt;P&gt;I'd start here to understand how this works:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk162635" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk162635&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 01:05:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-blade-Endpoint-security-client/m-p/236074#M2708</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-18T01:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: Compliance blade Endpoint security client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-blade-Endpoint-security-client/m-p/236332#M2709</link>
      <description>&lt;P&gt;Thank you for answer!&lt;/P&gt;&lt;P&gt;But, i read this sk, and still don't understand, why this function don't work?&lt;/P&gt;&lt;P&gt;My VPN-client now &lt;STRONG&gt;Restricted by compliance&amp;nbsp;blade&lt;/STRONG&gt;, but anyway has access to internal network through VPN (icmp and rdp as minimum). Why this access not blocked?!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 11:33:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-blade-Endpoint-security-client/m-p/236332#M2709</guid>
      <dc:creator>ajax</dc:creator>
      <dc:date>2024-12-19T11:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: Compliance blade Endpoint security client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-blade-Endpoint-security-client/m-p/236440#M2710</link>
      <description>&lt;P&gt;Have you configured any of the settings here?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28940i3F16A56D5E84A51A/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 21:15:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-blade-Endpoint-security-client/m-p/236440#M2710</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-19T21:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: Compliance blade Endpoint security client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-blade-Endpoint-security-client/m-p/236462#M2711</link>
      <description>&lt;P&gt;Option "Apply Secure Configuration Verification" is&amp;nbsp;not enabled.&lt;/P&gt;&lt;P&gt;In my Compliance config , i use "VPN client verification process will use Endpoint Security Compliance" (not VPN SCV compliance), therefore i think that "Apply Secure&amp;nbsp;Configuration Verification" don't needed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or needed?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 08:59:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-blade-Endpoint-security-client/m-p/236462#M2711</guid>
      <dc:creator>ajax</dc:creator>
      <dc:date>2024-12-20T08:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: Compliance blade Endpoint security client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-blade-Endpoint-security-client/m-p/236544#M2712</link>
      <description>&lt;P&gt;I agree, that might not be the right place.&lt;BR /&gt;What policy do you have for Restricted?&lt;BR /&gt;This is where you define what your clients can do when they are in a Restricted state.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28948iDDF4704DE6D7E114/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 21:29:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-blade-Endpoint-security-client/m-p/236544#M2712</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-20T21:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: Compliance blade Endpoint security client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-blade-Endpoint-security-client/m-p/236545#M2713</link>
      <description>&lt;P&gt;Wow, i don't have Harmony Endpoint Server &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have just CheckPoint 81.10 (&lt;SPAN&gt;JHF take 170) with Evaluate License and enabled blades:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;On SMS:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Endpoint Policy Management&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Compliance&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;On SG:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;IPSEC VPN (with Policy Server)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mobile Access&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And i thoght this blades enough for deploying Harmony Endpoint Client to remote users and Compliance check..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I need Harmony Endpoint Server product additionally? Without him it's can't work?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 22:30:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-blade-Endpoint-security-client/m-p/236545#M2713</guid>
      <dc:creator>ajax</dc:creator>
      <dc:date>2024-12-20T22:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: Compliance blade Endpoint security client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-blade-Endpoint-security-client/m-p/236738#M2714</link>
      <description>&lt;P&gt;Because you are using an eval license AND enabled Endpoint Policy Management, you do, in fact, have Endpoint Management. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;Endpoint is managed with SmartEndpoint and/or a separate WebUI.&lt;BR /&gt;The screenshot I showed was from Infinity Portal, but I believe it's similar on the local WebUI.&lt;/P&gt;
&lt;P&gt;Compliance checks can be done with one of two methods:&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Endpoint Compliance (requires Harmony Endpoint management, which must be licensed).&lt;/LI&gt;
&lt;LI&gt;SCV (does not require Harmony Endpoint, but requires crafting a local.csv file). See:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk38702" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk38702&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Compliance (as configured on the Management object) has nothing to do with Endpoint or VPN.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk120256" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk120256&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If your intention is not to have Harmony Endpoint management, then you should work with SCV, and the screenshot I provided above definitely applies.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Dec 2024 20:19:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-blade-Endpoint-security-client/m-p/236738#M2714</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-23T20:19:36Z</dc:date>
    </item>
  </channel>
</rss>

