Endpoint Firewall Internet Control

Hello Checkmates,

I've been out of the Checkpoint game since R75, now I'm implementing a new pair of CP 5600s with NGTX and need some help on the Endpoint client.

Basically I have a full tunnel setup and users are able to access the internet & corporate resources over the VPN just fine.

However, I want to block internet access when they are not on VPN. Basically the only way they can get internet is through the VPN connection. Is this achievable with the Endpoint client, or do I need to do some Windows GPO snafu?


Thanks in advance!

This should be possible, yes, by appropriately configuring the disconnected policy on the client.
There is also a Hotspot option to temporarily open the firewall to allow users to register with a Hotspot portal.
