<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic keepalive on Endpoint Security in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/keepalive-on-Endpoint-Security/m-p/223188#M3332</link>
    <description>&lt;P&gt;The user upgraded to E88.50 and we are still seeing the issue.&amp;nbsp; ICMP pings from his PC or router to the gateway.&amp;nbsp;&amp;nbsp; Is there some kind of keepalive ping check on Endpoint Security I can have him uncheck?&amp;nbsp;&amp;nbsp; We are trying to figure out what's sending pings back to the remote access gateway (which are dropped) dest-unreach (ICMP).&amp;nbsp; We don't allow ping.&lt;/P&gt;</description>
    <pubDate>Fri, 09 Aug 2024 20:58:53 GMT</pubDate>
    <dc:creator>Daniel_Kavan</dc:creator>
    <dc:date>2024-08-09T20:58:53Z</dc:date>
    <item>
      <title>keepalive on Endpoint Security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/keepalive-on-Endpoint-Security/m-p/223188#M3332</link>
      <description>&lt;P&gt;The user upgraded to E88.50 and we are still seeing the issue.&amp;nbsp; ICMP pings from his PC or router to the gateway.&amp;nbsp;&amp;nbsp; Is there some kind of keepalive ping check on Endpoint Security I can have him uncheck?&amp;nbsp;&amp;nbsp; We are trying to figure out what's sending pings back to the remote access gateway (which are dropped) dest-unreach (ICMP).&amp;nbsp; We don't allow ping.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 20:58:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/keepalive-on-Endpoint-Security/m-p/223188#M3332</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2024-08-09T20:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: keepalive on Endpoint Security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/keepalive-on-Endpoint-Security/m-p/223190#M3333</link>
      <description>&lt;P&gt;Yes, there is and it actually has absolutely zero to do with endpoint version. Its in global properties and its refered to below.&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://downloads.checkpoint.com/dc/download.htm?ID=60345" target="_blank"&gt;http://downloads.checkpoint.com/dc/download.htm?ID=60345&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="x_MsoNormal"&gt;To configure tunnel idleness:&lt;/P&gt;
&lt;P class="x_MsoNormal"&gt;1. Connect to the Security Management Server with GuiDBedit.&lt;/P&gt;
&lt;P class="x_MsoNormal"&gt;2. Open the Global Properties &amp;gt; properties &amp;gt; firewall_properties object.&lt;/P&gt;
&lt;P class="x_MsoNormal"&gt;3. Find disconnect_on_idle and these parameters:&lt;/P&gt;
&lt;P class="x_MsoNormal"&gt;&amp;nbsp; • do_not_check_idleness_on_icmp_packets&lt;/P&gt;
&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&amp;nbsp;• do_not_check_idleness_on_these_services - Enter the port numbers for the services that you want to ignore when idleness is checked.&lt;/P&gt;
&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&amp;nbsp;• enable_disconnect_on_idle - to enable the feature&lt;/P&gt;
&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&amp;nbsp;• idle_timeout_in_minutes&lt;/P&gt;
&lt;P class="x_MsoNormal"&gt;4. Save and install the policy.&lt;/P&gt;
&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="x_MsoNormal"&gt;Btw, there is ping option there you can change, so if user is somewhat savvy, they can always keep pinging say google dns in cmd and tunnel will NEVER time out, though its supposed to say after 60 mins (just as an example)&lt;/P&gt;</description>
      <pubDate>Sat, 10 Aug 2024 00:38:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/keepalive-on-Endpoint-Security/m-p/223190#M3333</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-10T00:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: keepalive on Endpoint Security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/keepalive-on-Endpoint-Security/m-p/223327#M3334</link>
      <description>&lt;P&gt;Thanks, that 60345 link isn't opening for me.&amp;nbsp; &amp;nbsp; I'm looking for something to change on the client side actually.&amp;nbsp; &amp;nbsp;Is there a tunnel keep alive check box for example?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 13:30:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/keepalive-on-Endpoint-Security/m-p/223327#M3334</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2024-08-12T13:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: keepalive on Endpoint Security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/keepalive-on-Endpoint-Security/m-p/223331#M3335</link>
      <description>&lt;P&gt;There is enable always connect, but in order for client to be able to check that, it has to be enabled in global properties, under endpoint options. Except in your case, it should say always connected.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27210iF3BFCB45BE16F536/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27211i6666EAD8FFDE1327/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 13:42:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/keepalive-on-Endpoint-Security/m-p/223331#M3335</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-12T13:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: keepalive on Endpoint Security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/keepalive-on-Endpoint-Security/m-p/223332#M3336</link>
      <description>&lt;P&gt;It is just RAS VPN Admin guide, you can look it up as HTML page under support.checkpoint.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 13:56:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/keepalive-on-Endpoint-Security/m-p/223332#M3336</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-08-12T13:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: keepalive on Endpoint Security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/keepalive-on-Endpoint-Security/m-p/223336#M3337</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/599"&gt;@Daniel_Kavan&lt;/a&gt;&amp;nbsp;Glad we can help mate. If anything else, just update the thread.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 14:25:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/keepalive-on-Endpoint-Security/m-p/223336#M3337</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-12T14:25:00Z</dc:date>
    </item>
  </channel>
</rss>

