<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connection Awareness in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-Awareness/m-p/210887#M3913</link>
    <description>&lt;P&gt;To be honest, it's not clear what the intended goal of all this is.&lt;BR /&gt;Can you explain?&lt;/P&gt;</description>
    <pubDate>Tue, 09 Apr 2024 23:02:46 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-04-09T23:02:46Z</dc:date>
    <item>
      <title>Connection Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-Awareness/m-p/210139#M3911</link>
      <description>&lt;P&gt;According to the documentation, we can configure a ping to a destination or HTTP/S GET done every 30 seconds.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We looked at this feature for a fully segmented network behind a Quantum cluster doing the full Threat Prevention policing already.&lt;/P&gt;
&lt;P&gt;We want to adjust some settings to avoid redundant use on some blades and extra processing time for users, for this we are looking at a connected/disconnected policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are the challenges we found:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The documentation doesn't speak much about ICMP behaviour, what is the frequency of pings and when is the system considered to be disconnected or connected again&lt;/LI&gt;
&lt;LI&gt;For users behind VPN using split-tunnelling, we need some extra configuration like blocking ping to the inside destination in the firewall policy which looks a bit like a DIY approach&lt;/LI&gt;
&lt;LI&gt;For our larger deployments with hundreds of endpoints, we are creating a sort of DDOS setup to an inside system&lt;/LI&gt;
&lt;LI&gt;The client says Online when it can reach Internet but it's not clear for end-users or administrator if we are operating in connected or disconnected mode and its tracking&lt;/LI&gt;
&lt;LI&gt;We need to set up at least two destinations to avoid having all clients to switch to disconnected should for instance the probed system require a reboot or similar which doubles the traffic.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our clients would prefer a posture-based approach policy, like membership of subnet X and domain Y with DNS server being Z and assign them to a connected or disconnected status, which would then also address the situation of VPN users in split-tunneling.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Mar 2024 22:48:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-Awareness/m-p/210139#M3911</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2024-03-31T22:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: Connection Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-Awareness/m-p/210876#M3912</link>
      <description>&lt;P&gt;you made this post in the wrong place (endpoint location). I suggest you post this in Quantum location.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 16:07:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-Awareness/m-p/210876#M3912</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2024-04-09T16:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: Connection Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-Awareness/m-p/210887#M3913</link>
      <description>&lt;P&gt;To be honest, it's not clear what the intended goal of all this is.&lt;BR /&gt;Can you explain?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 23:02:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-Awareness/m-p/210887#M3913</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-04-09T23:02:46Z</dc:date>
    </item>
    <item>
      <title>Re: Connection Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-Awareness/m-p/210895#M3914</link>
      <description>&lt;P&gt;This is about connected/disconnected endpoint policy mode.&lt;/P&gt;
&lt;P&gt;We are providing complete security packages to our customers with Quantum and Harmony EpmaaS.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The firewalls are doing full segmentation and all the blades are activated.&lt;/P&gt;
&lt;P&gt;On Harmony Endpoint with EpmaaS, we would like to avoid running the full suite when users are in the office behind the firewall, instead a lighter version of the policy. When they're outside of the perimeter, the enhanced endpoint policy should be enforced.&lt;/P&gt;
&lt;P&gt;However determine the connection awareness status isn't as straightforward as the documentation would imply, based on our tests and what is described in the initial post.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_HarmonyEndpointWebManagement_AdminGuide/Content/Topics-HEPWM-R81.10/Connection-Awareness.htm?TocPath=Configuring%20Endpoint%20Policy%7C_____7" target="_blank" rel="noopener"&gt;Connection Awareness&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 07:21:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-Awareness/m-p/210895#M3914</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2024-04-10T07:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: Connection Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-Awareness/m-p/210897#M3915</link>
      <description>&lt;P&gt;This post is for Harmony Endpoint Connection Awareness, I understand it wasn't directly clear from the start.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 07:12:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connection-Awareness/m-p/210897#M3915</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2024-04-10T07:12:04Z</dc:date>
    </item>
  </channel>
</rss>

