<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cluster Migration and Endpoint Security VPN Users Move? in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224789#M3276</link>
    <description>&lt;P&gt;That is not correct -&amp;nbsp; you are using Harmony Endpoint Security E8X with VPN Blade. &lt;SPAN class="css-13y3t3g"&gt;&lt;SPAN class="css-vy7rm"&gt;sk103440&lt;/SPAN&gt;&lt;/SPAN&gt; is only for &lt;SPAN class="css-1tluag8"&gt;Endpoint Security VPN &amp;amp; SecuRemote that you do not use.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="css-1tluag8"&gt;But correctly you assume that a push operation will deploy a new vpnj site - you have&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P class="Menu_Options"&gt;Add VPN Site&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="Menu_Options"&gt;Remove VPN Site&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Look here, you have to scroll down and click Agent Settings: &lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-Common-for-HEP/Performing-Push-Operations.htm?Highlight=Adds%20or%20removes%20a%20VPN%20site" target="_blank"&gt;https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-Common-for-HEP/Performing-Push-Operations.htm?Highlight=Adds%20or%20removes%20a%20VPN%20site&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Aug 2024 10:50:34 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2024-08-28T10:50:34Z</dc:date>
    <item>
      <title>Cluster Migration and Endpoint Security VPN Users Move?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224687#M3273</link>
      <description>&lt;P&gt;We're in the middle of a cluster migration and have built a separate cluster with new public IPs for VPN users.&amp;nbsp; Is there still no easy way to push out a new config for end-users so that the next time they connect, it goes to our new cluster and VPN?&amp;nbsp; We initially point them to a DNS record but it appears that after the initial setup, it's hard-coding an IP address so messing with DNS is not going to work.&lt;/P&gt;&lt;P&gt;I ran across this SK:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk103440" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk103440&lt;/A&gt;&amp;nbsp;but that looks to only work after manually touching the end-user once to reconfigure the sites.&lt;/P&gt;&lt;P&gt;Is a manual touch or a push of an uninstall/reinstall with proper sites the only way?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 21:43:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224687#M3273</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2024-08-27T21:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Migration and Endpoint Security VPN Users Move?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224747#M3274</link>
      <description>&lt;P&gt;Do you use Remote Access (Enterprise VPN client with VPN blade only) or Harmony Endpoint ? You did not post this in Endpoint, so i assume it is VPN client only. Abyway, manual touch or a push of an uninstall/reinstall with proper sites is the only way to achieve the goal you have.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 08:30:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224747#M3274</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-08-28T08:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Migration and Endpoint Security VPN Users Move?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224782#M3275</link>
      <description>&lt;P&gt;Correct,&amp;nbsp;Endpoint Security E8X with VPN Blade.&amp;nbsp; No Harmony involved.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 10:18:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224782#M3275</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2024-08-28T10:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Migration and Endpoint Security VPN Users Move?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224789#M3276</link>
      <description>&lt;P&gt;That is not correct -&amp;nbsp; you are using Harmony Endpoint Security E8X with VPN Blade. &lt;SPAN class="css-13y3t3g"&gt;&lt;SPAN class="css-vy7rm"&gt;sk103440&lt;/SPAN&gt;&lt;/SPAN&gt; is only for &lt;SPAN class="css-1tluag8"&gt;Endpoint Security VPN &amp;amp; SecuRemote that you do not use.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="css-1tluag8"&gt;But correctly you assume that a push operation will deploy a new vpnj site - you have&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P class="Menu_Options"&gt;Add VPN Site&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="Menu_Options"&gt;Remove VPN Site&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Look here, you have to scroll down and click Agent Settings: &lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-Common-for-HEP/Performing-Push-Operations.htm?Highlight=Adds%20or%20removes%20a%20VPN%20site" target="_blank"&gt;https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-Common-for-HEP/Performing-Push-Operations.htm?Highlight=Adds%20or%20removes%20a%20VPN%20site&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 10:50:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224789#M3276</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-08-28T10:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Migration and Endpoint Security VPN Users Move?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224796#M3277</link>
      <description>&lt;P&gt;This is a screenshot of our client.&amp;nbsp; Don't see anything about Harmony unless later versions they changed the name?&lt;/P&gt;&lt;P&gt;Either way, sounds like a manual touch or a pushed uninstall/install.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 11:00:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224796#M3277</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2024-08-28T11:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Migration and Endpoint Security VPN Users Move?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224839#M3278</link>
      <description>&lt;P&gt;No, see &lt;A href="https://support.checkpoint.com/results/sk/sk117536" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk117536&lt;/A&gt; - Harmony is not shown everywhere, but this is now a Harmony product. Manual touch is not possible as &lt;SPAN class="css-13y3t3g"&gt;&lt;SPAN class="css-vy7rm"&gt;sk103440&lt;/SPAN&gt;&lt;/SPAN&gt; does not apply as &lt;EM&gt;$FWDIR/conf/trac_client_1.ttm&lt;/EM&gt; file on GW does not exist with Endpoint. But you can delete the VPN site and replace it using push operations.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="infinity2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27392iBB63965F83C5CCD2/image-size/large?v=v2&amp;amp;px=999" role="button" title="infinity2.png" alt="infinity2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 14:06:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224839#M3278</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-08-28T14:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Migration and Endpoint Security VPN Users Move?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224877#M3279</link>
      <description>&lt;P&gt;If you can run scripts on remote computers, you can update trac.config with the appropriate settings.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Updating-User-Sites-with-Update-Configuration-Tool.htm?TocPath=Setting%20Up%20Remote%20Access%20Clients%7CUpdating%20User%20Sites%20with%20the%20Update%20Configuration%20Tool%7C_____0" target="_blank"&gt;https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Updating-User-Sites-with-Update-Configuration-Tool.htm?TocPath=Setting%20Up%20Remote%20Access%20Clients%7CUpdating%20User%20Sites%20with%20the%20Update%20Configuration%20Tool%7C_____0&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 17:40:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224877#M3279</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-28T17:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Migration and Endpoint Security VPN Users Move?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224902#M3281</link>
      <description>&lt;P&gt;Looking at the note (&lt;SPAN class=""&gt;Important&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- The client version in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Administrator&lt;/SPAN&gt;'s computer must be the same as the version on the user's computer.) We do have multiple versions out there... 84.XX, 85.XX, 86.XX,etc.&amp;nbsp; We need a different config for every single build that's different?&amp;nbsp; Could take a little bit of work but might be worth it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 19:30:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224902#M3281</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2024-08-28T19:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Migration and Endpoint Security VPN Users Move?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224904#M3282</link>
      <description>&lt;P&gt;If you can run the old and the new cluster at the same time you can use MultipleEntryPoint feature, called MEP. Both clusters should have the same encryption domain for remote access but different office mode IPs to avoid routing problems for the clients. With MEP you can use both clusters in active/active, active/backup, first to response….. The clients get‘s the new gateway IP if they connect to the old system once and then they use both gateways regarding your MEP configuration. If the old system is gone and did not response the new one is used.&lt;/P&gt;
&lt;P&gt;&lt;A title="Multiple Entry Points for Remote Access VPNs" href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/MEP.htm" target="_blank" rel="noopener"&gt;Multiple Entry Points for Remote Access VPNs&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 20:09:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224904#M3282</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2024-08-28T20:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Migration and Endpoint Security VPN Users Move?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224905#M3283</link>
      <description>&lt;P&gt;Yes, they're both fully operational at the moment and I'm connected to the new cluster VPN right now.&amp;nbsp; Different OM subnet like you said so it can route internally but almost everything else is the same.&amp;nbsp; The new cluster has it's own Management Server also... if that matters?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 20:15:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Cluster-Migration-and-Endpoint-Security-VPN-Users-Move/m-p/224905#M3283</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2024-08-28T20:15:37Z</dc:date>
    </item>
  </channel>
</rss>

