<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable device posture assessment to connect RA VPN in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-device-posture-assessment-to-connect-RA-VPN/m-p/120093#M8535</link>
    <description>&lt;P&gt;Ok got it. Then I'll have a look at Endpoint Compliance.&lt;/P&gt;&lt;P&gt;So for the licensing model, does that mean we can enable that on our SMS recently upgraded to R81 ? Or does the sentence 'modern management SKU' refers to something else.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it can be enabled on our Management appliance, is that recommended ? Or is it preferable to have it separated ? Do you have any requirement that would allow us to determine if our appliance is sized appropriately to host Endpoint Management ?&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;</description>
    <pubDate>Tue, 01 Jun 2021 15:03:32 GMT</pubDate>
    <dc:creator>Ob1lan</dc:creator>
    <dc:date>2021-06-01T15:03:32Z</dc:date>
    <item>
      <title>Enable device posture assessment to connect RA VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-device-posture-assessment-to-connect-RA-VPN/m-p/120054#M8529</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Our management came with a new requirement : to be able to do device posture assessment/healthcheck before allowing to connect our Remote VPN gateways.&lt;/P&gt;&lt;P&gt;I'm a bit confused about the licenses needed for this, what needs to be configured on the gateways, and what client software is needed.&lt;/P&gt;&lt;P&gt;Currently, we use Endpoint Security VPN Standalone, and our VPN gateways are installed with R80.30.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is what I see on the licenses details for one of our gateway:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-06-01 at 13.50.59.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11991i9D1B25D5DAF3B624/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2021-06-01 at 13.50.59.png" alt="Screenshot 2021-06-01 at 13.50.59.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Basically we would like to avoid devices without certain OS patches, certificate installed, etc... to connect our network. Also, would be great to allow policies to be applied to AD groups.&lt;/P&gt;&lt;P&gt;Could someone advise on that, is there a guide somewhere ?&lt;/P&gt;&lt;P&gt;Thanks in advance !&lt;/P&gt;&lt;P&gt;EDIT : we have both Windows and MacOS clients, and would like to have the same kind of security checks features for both OS.&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 14:12:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-device-posture-assessment-to-connect-RA-VPN/m-p/120054#M8529</guid>
      <dc:creator>Ob1lan</dc:creator>
      <dc:date>2021-06-01T14:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: Enable device posture assessment to connect RA VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-device-posture-assessment-to-connect-RA-VPN/m-p/120060#M8530</link>
      <description>&lt;P&gt;Check Point calls this Secure Configuration Verification (SCV).&lt;/P&gt;&lt;P&gt;The whitepaper &lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/White-Paper-Check-Point-Compliance-Checking-with-Secure/m-p/57123#M1737" target="_self"&gt;linked here&lt;/A&gt; is a pretty good starting point.&amp;nbsp; There is also&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk147416&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_self"&gt;sk147416&lt;/A&gt; which contains a wealth of information and examples.&lt;/P&gt;&lt;P&gt;Lastly - I &lt;A href="https://namitguy.blogspot.com/2020/04/implementing-secure-client-verification.html" target="_self"&gt;wrote a blog post&lt;/A&gt; with step-by-step examples on how to do simple SCV (domain membership check) using only the standalone VPN client and a Check Point gateway.&lt;/P&gt;&lt;P&gt;Hope it helps,&lt;BR /&gt;Ruan&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 12:41:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-device-posture-assessment-to-connect-RA-VPN/m-p/120060#M8530</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2021-06-01T12:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: Enable device posture assessment to connect RA VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-device-posture-assessment-to-connect-RA-VPN/m-p/120068#M8531</link>
      <description>&lt;P&gt;SCV as described by&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9028"&gt;@Ruan_Kotze&lt;/a&gt;&amp;nbsp;is one option, which is supported with Mobile Access licenses.&lt;BR /&gt;The other option is Endpoint Compliance, which requires either an ACCESS license or one of the Harmony Endpoint/SBA SKUs.&lt;BR /&gt;This offers a bit more granularity and also supports Mac clients.&lt;BR /&gt;It requires using Endpoint Management&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 13:49:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-device-posture-assessment-to-connect-RA-VPN/m-p/120068#M8531</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-01T13:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: Enable device posture assessment to connect RA VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-device-posture-assessment-to-connect-RA-VPN/m-p/120070#M8532</link>
      <description>&lt;P&gt;Thanks a lot. So SCV doesn't support MacOS at all ? Also, Endpoint Management is something I need to install in the CMA or a standalone instance ? I'll check what license level we have and what can be done.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 14:00:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-device-posture-assessment-to-connect-RA-VPN/m-p/120070#M8532</guid>
      <dc:creator>Ob1lan</dc:creator>
      <dc:date>2021-06-01T14:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: Enable device posture assessment to connect RA VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-device-posture-assessment-to-connect-RA-VPN/m-p/120074#M8533</link>
      <description>&lt;P&gt;Thanks, I'll consider those ressources carefully. Something I missed in my original request is we have both Windows clients and MacOS clients. I believe SCV only works for Windows ? How to handle same level of security checks for MacOS clients ?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 14:12:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-device-posture-assessment-to-connect-RA-VPN/m-p/120074#M8533</guid>
      <dc:creator>Ob1lan</dc:creator>
      <dc:date>2021-06-01T14:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Enable device posture assessment to connect RA VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-device-posture-assessment-to-connect-RA-VPN/m-p/120090#M8534</link>
      <description>&lt;P&gt;SCV currently does not support Mac, correct.&lt;BR /&gt;This will require the use of Endpoint Compliance (and Endpoint Management).&lt;/P&gt;
&lt;P&gt;Endpoint Management can be acquired a couple different ways:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;It's included in modern management SKUs (just needs to be enabled)&lt;/LI&gt;
&lt;LI&gt;If you want to run on a separate system from your network management, it requires a separate license&lt;/LI&gt;
&lt;LI&gt;If you purchase(d) SBA or Harmony SKUs, Cloud-based management is included&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 01 Jun 2021 14:59:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-device-posture-assessment-to-connect-RA-VPN/m-p/120090#M8534</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-01T14:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: Enable device posture assessment to connect RA VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-device-posture-assessment-to-connect-RA-VPN/m-p/120093#M8535</link>
      <description>&lt;P&gt;Ok got it. Then I'll have a look at Endpoint Compliance.&lt;/P&gt;&lt;P&gt;So for the licensing model, does that mean we can enable that on our SMS recently upgraded to R81 ? Or does the sentence 'modern management SKU' refers to something else.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it can be enabled on our Management appliance, is that recommended ? Or is it preferable to have it separated ? Do you have any requirement that would allow us to determine if our appliance is sized appropriately to host Endpoint Management ?&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 15:03:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-device-posture-assessment-to-connect-RA-VPN/m-p/120093#M8535</guid>
      <dc:creator>Ob1lan</dc:creator>
      <dc:date>2021-06-01T15:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: Enable device posture assessment to connect RA VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-device-posture-assessment-to-connect-RA-VPN/m-p/120097#M8536</link>
      <description>&lt;P&gt;The output of cplic print on your management can determine if you're licensed for Endpoint Management or not.&lt;BR /&gt;In terms of sizing, it will obviously require more memory to also run Endpoint Management.&lt;BR /&gt;However, given you'd be using it only for Endpoint Compliance, the overall impact should be minimal.&lt;BR /&gt;If you're using other Endpoint Management features, I'd separate them.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your Check Point SE should be able to provide more specific guidance for your situation.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Jun 2021 15:14:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-device-posture-assessment-to-connect-RA-VPN/m-p/120097#M8536</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-01T15:14:51Z</dc:date>
    </item>
  </channel>
</rss>

