<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Compliance Endpoint Security in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-Endpoint-Security/m-p/112936#M9060</link>
    <description>&lt;P&gt;1. This can be done with SCV or Endpoint Compliance, the latter of which is easier to configure and works on Macs and PCs (SCV is Windows only currently).&lt;/P&gt;
&lt;P&gt;2. You would have to “route all traffic” back to headquarters, which may not be desirable. That said it would be possible using the other Harmony components to achieve a similarly configured policy for VPN endpoints without routing all traffic back to the corporate office.&lt;/P&gt;
&lt;P&gt;3. You can restrict which types of VPN clients that can connect globally to prevent mobile phones (or other client types) from connecting if desired. This doesn’t even require Endpoint Compliance.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Mar 2021 07:15:17 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-03-10T07:15:17Z</dc:date>
    <item>
      <title>Compliance Endpoint Security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-Endpoint-Security/m-p/112921#M9059</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;We have a customer that have the most of their employes working remote. In addition, they have configurate the Remote Access VPN, and now they have a question about the compliance. For example, I have this questions:&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Is possible that compliance can validate that only can connect to Remote VPN desktops of domain?&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Is possible if the connect is sucessful, take the policies that are configurated in the firewall as if the employ is in the LAN company?&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Is possible block or not allowed connections of cellphones?&lt;/P&gt;&lt;P&gt;I was reading about Endppoint Security Compliance on Demand that can be configurated in global propierties, and another solution is SCV Secure Configuration Validation altough is like me more hard. What is the best way? or What tool offer us configurate the requierements?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your advices.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Mar 2021 02:27:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-Endpoint-Security/m-p/112921#M9059</guid>
      <dc:creator>Julian_Sanchez</dc:creator>
      <dc:date>2021-03-10T02:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: Compliance Endpoint Security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-Endpoint-Security/m-p/112936#M9060</link>
      <description>&lt;P&gt;1. This can be done with SCV or Endpoint Compliance, the latter of which is easier to configure and works on Macs and PCs (SCV is Windows only currently).&lt;/P&gt;
&lt;P&gt;2. You would have to “route all traffic” back to headquarters, which may not be desirable. That said it would be possible using the other Harmony components to achieve a similarly configured policy for VPN endpoints without routing all traffic back to the corporate office.&lt;/P&gt;
&lt;P&gt;3. You can restrict which types of VPN clients that can connect globally to prevent mobile phones (or other client types) from connecting if desired. This doesn’t even require Endpoint Compliance.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Mar 2021 07:15:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-Endpoint-Security/m-p/112936#M9060</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-10T07:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Compliance Endpoint Security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-Endpoint-Security/m-p/112948#M9061</link>
      <description>&lt;P&gt;Regarding point 1 - I posted a detailed walkthrough of implementing domain membership validation for VPN clients&amp;nbsp;&lt;A href="https://namitguy.blogspot.com/2020/04/implementing-secure-client-verification.html" target="_blank" rel="noopener"&gt;on my blog&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Mar 2021 08:27:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-Endpoint-Security/m-p/112948#M9061</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2021-03-10T08:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: Compliance Endpoint Security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-Endpoint-Security/m-p/113219#M9062</link>
      <description>&lt;P&gt;Thank you for your answer. Relly useful. Only last question or doubt about the SCV or Endpoint Compliance. If I want to use Endpoint Compliance it work with the Endpoint Security only for VPN, the client normal or not?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn.PNG" style="width: 200px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10936i57B1811242171DE3/image-size/small?v=v2&amp;amp;px=200" role="button" title="vpn.PNG" alt="vpn.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="endpoint.PNG" style="width: 200px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10937i47FAA115C9131949/image-size/small?v=v2&amp;amp;px=200" role="button" title="endpoint.PNG" alt="endpoint.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Or for use Endpoint Compliance I need the agent of SBA? regards&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 18:24:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-Endpoint-Security/m-p/113219#M9062</guid>
      <dc:creator>Julian_Sanchez</dc:creator>
      <dc:date>2021-03-11T18:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: Compliance Endpoint Security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-Endpoint-Security/m-p/113220#M9063</link>
      <description>&lt;P&gt;The Check Point Mobile client is fine for what you want to do. You do not need the SBA.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 18:27:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-Endpoint-Security/m-p/113220#M9063</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2021-03-11T18:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: Compliance Endpoint Security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-Endpoint-Security/m-p/113253#M9064</link>
      <description>&lt;P&gt;Harmony Endpoint (formerly SandBlast Agent) does offer additional features.&lt;BR /&gt;Endpoint Security VPN is sufficient to use Compliance, however.&lt;BR /&gt;SCV can be used on Check Point Mobile (in addition to Endpoint Security VPN).&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 23:10:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-Endpoint-Security/m-p/113253#M9064</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-11T23:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: Compliance Endpoint Security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-Endpoint-Security/m-p/114471#M9065</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a question acording to the point 3. I disable or un check for preventing mobile phones. However if I want to give exclusions is possible? or block all phones?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 14:55:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-Endpoint-Security/m-p/114471#M9065</guid>
      <dc:creator>Julian_Sanchez</dc:creator>
      <dc:date>2021-03-24T14:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: Compliance Endpoint Security</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-Endpoint-Security/m-p/114493#M9066</link>
      <description>&lt;P&gt;The setting for which clients are allowed to connect is global (meaning either all of X-type clients are allowed to connect or none).&lt;BR /&gt;You can create (and use) Access Roles to control who is allowed to do what from what type of client once they are connected.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 17:22:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Compliance-Endpoint-Security/m-p/114493#M9066</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-24T17:22:18Z</dc:date>
    </item>
  </channel>
</rss>

