The only service that needs it is the "epc" service.
I imagine the file is locked as a result of Harmony Endpoint self-protection features.
Not sure these can be disabled, but you should confirm with TAC.
Have you tried creating the site using the "trac" binary I mentioned above?
For example to create a site from the gateway at 192.0.2.54 and naming it "MyVPNSite" in the UI, you issue the following command:
"/Library/Application Support/Checkpoint/Endpoint Security/Endpoint Connect/trac" create -s 192.0.2.254 -di MyVPNSite
Assuming you have some sort of remote execution capability on the Endpoints, this might be easier.