<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Preventing older vpn clients to connect to CP gateway in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234829#M2756</link>
    <description>&lt;P&gt;The version element is outlined in the SK I commented above, context is these settings / options&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_RemoteAccessVPN_AdminGuide/Topics-VPNRG/User-and-Client-Authentication.htm?tocpath=User%20and%20Client%20Authentication%20for%20Remote%20Access%7C_____2#Multiple_Login_Options_for_R80.xx_Gateways" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_RemoteAccessVPN_AdminGuide/Topics-VPNRG/User-and-Client-Authentication.htm?tocpath=User%20and%20Client%20Authentication%20for%20Remote%20Access%7C_____2#Multiple_Login_Options_for_R80.xx_Gateways&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Dec 2024 22:33:53 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2024-12-05T22:33:53Z</dc:date>
    <item>
      <title>Preventing older vpn clients from connecting to CP gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234813#M2752</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;Just wondering about this and wanted to clarify something. Customer was asking about option on the gateway, vpn clients -&amp;gt; authentication -&amp;gt; allow older clients to connect to this gateway.&lt;/P&gt;
&lt;P&gt;Now, when we check it, it shows its referring to actual legacy VPN (standalone clients) and NOT harmony endpoint. Their only auth option currently is user+password.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any confirmation anywhere what is LOWEST vpn client version that could connect if say this option was indeed enabled?&lt;/P&gt;
&lt;P&gt;Also, is there any way to disable any legacy vpn client from actually connecting and ONLY allow harmony endpoint?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 00:07:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234813#M2752</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-06T00:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing older vpn clients to connect to CP gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234816#M2753</link>
      <description>&lt;P&gt;For what its worth, this is an explanation from smart console about it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28679i20AC6E4F4524B9BA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 20:15:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234816#M2753</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-05T20:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing older vpn clients to connect to CP gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234822#M2754</link>
      <description>&lt;P&gt;If I remember correctly the setting is relevant to the client versions specified in&amp;nbsp;&lt;SPAN&gt;sk111583.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;With R82 forcing IKEv2 for remote access would have a similar effect for older client versions earlier than E88.40 aswell.&lt;/P&gt;
&lt;P&gt;Similarity not all client types support SAML, so even without specific options you could achieve an outcome through these choices perhaps.&lt;/P&gt;
&lt;P&gt;See also: Gateway Properties &amp;gt; Mobile Access &amp;gt; Allowed Clients&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 22:50:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234822#M2754</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-12-05T22:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing older vpn clients to connect to CP gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234827#M2755</link>
      <description>&lt;P&gt;Hey Chris,&lt;/P&gt;
&lt;P&gt;Thanks for the response. I think customer is simply wondering what is the LOWEST client version that could connect say if that option was enabled and 2nd, is there any way to prevent anyone who is NOT using harmony endpoint client to conect to the gateway?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 22:23:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234827#M2755</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-05T22:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing older vpn clients to connect to CP gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234829#M2756</link>
      <description>&lt;P&gt;The version element is outlined in the SK I commented above, context is these settings / options&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_RemoteAccessVPN_AdminGuide/Topics-VPNRG/User-and-Client-Authentication.htm?tocpath=User%20and%20Client%20Authentication%20for%20Remote%20Access%7C_____2#Multiple_Login_Options_for_R80.xx_Gateways" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_RemoteAccessVPN_AdminGuide/Topics-VPNRG/User-and-Client-Authentication.htm?tocpath=User%20and%20Client%20Authentication%20for%20Remote%20Access%7C_____2#Multiple_Login_Options_for_R80.xx_Gateways&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 22:33:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234829#M2756</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-12-05T22:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing older vpn clients to connect to CP gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234830#M2757</link>
      <description>&lt;P&gt;K thank you, I think that answers my 1st question. Now, for the 2nd one, any way to prevent anyone NOT using harmony endpoint client to connect?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 00:08:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234830#M2757</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-06T00:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing older vpn clients to connect to CP gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234832#M2758</link>
      <description>&lt;P&gt;There are different options available for this requirement:&lt;/P&gt;
&lt;P&gt;1. VPN Clients option - Allows restricting some client types&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RA Clients.jpg" style="width: 760px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28680i096BB24E4ABA153E/image-size/large?v=v2&amp;amp;px=999" role="button" title="RA Clients.jpg" alt="RA Clients.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;2. Using SCV / Compliance Policies in particular the method enforceable via HEP.&lt;/P&gt;
&lt;P&gt;(Note here their is a reliance on the Desktop Firewall / Desktop Policy allowing necessary comms to allow clients checks to occur per sk164861)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3.&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;sk108892 -&amp;nbsp;How to verify the integrity of Endpoint Remote Access VPN clients (Appendix 5)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4. Machine Cert Auth for further enhanced security.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 00:38:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234832#M2758</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-12-06T00:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing older vpn clients to connect to CP gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234842#M2759</link>
      <description>&lt;P&gt;Thanks Chris. So I know for option 1, I was thinking if that may actually work. Would that technically prevent anyone using legacy endpoint vpn from connecting and still allow people using harmony endpoint to connect?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 02:12:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234842#M2759</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-06T02:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing older vpn clients from connecting to CP gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234855#M2760</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;maybe you can try with restrictions via the access-role....&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="RemoteAccess_Clients.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28686iEEFB83F26E0D97DB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RemoteAccess_Clients.png" alt="RemoteAccess_Clients.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 08:26:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234855#M2760</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2024-12-06T08:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing older vpn clients from connecting to CP gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234883#M2761</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;! I just want to be sure that option you gave and option 1&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;provided would ineed stop ONLY legacu endpoint vpn from connecting and allow harmony endpoint. Let me see if my colleague I had been working with on this and I can test this in the lab to confirm.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 12:31:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-older-vpn-clients-from-connecting-to-CP-gateway/m-p/234883#M2761</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-06T12:31:18Z</dc:date>
    </item>
  </channel>
</rss>

